bug-bounty437
google355
xss346
microsoft282
facebook246
apple172
exploit163
rce160
malware102
account-takeover95
cve91
csrf83
writeup79
bragging-post79
browser77
privilege-escalation68
react60
authentication-bypass57
cloudflare54
dos53
node52
ssrf51
docker51
phishing49
aws48
access-control47
oauth45
smart-contract45
supply-chain44
ethereum43
defi42
web342
sql-injection41
lfi37
idor34
smart-contract-vulnerability32
web-application31
info-disclosure31
clickjacking31
race-condition31
reverse-engineering31
wordpress30
vulnerability-disclosure30
cloud29
information-disclosure28
burp-suite28
solidity27
web-security27
pentest26
ctf26
0
8/10
A researcher discovered a sandbox escape vulnerability in HackerEarth's Theia IDE by leveraging the 'Task: Run selected text' command to gain terminal access, subsequently achieving RCE and exfiltration of AWS credentials and SSL certificates from the underlying ECS container through metadata service exploitation.
sandbox-escape
rce
remote-code-execution
ide-security
theia-ide
vs-code
aws-credentials
metadata-service
ecs-metadata
ssl-certificate-disclosure
responsible-disclosure
bug-bounty
privilege-escalation
information-disclosure
HackerEarth
Theia IDE
VS Code
Jatin Dhankhar
Puma Scan
AWS