HACK THE BOX NeuroSync
NeuroSync
25th March 2025
Prepared By: B0lkas & Lean
Challenge Author(s): B0lkas & Lean
Difficulty: Hard
Classification: Official
Synopsis
Next.JS authentication bypass (CVE-2025-29927) => Curl SSRF => LFI with filter bypass =>
Leakage of secret => Redis injection => Issuing of arbitrary com...


