Chained hardcoded API key and pickle RCE gave root and full cloud takeover on a Meta service
evilsocket · x · 2026-09-29
Security researcher zonduu published a full write-up of an attack chain used at Meta's in-person live hacking event in Taiwan, shared by evilsocket:
- Entry: a GraphRAG service in Meta's AI meeting/assistant stack had an API key hardcoded as a fallback default in a client-side Next.js bundle.
- Chain: the key plus two path traversals and an unsafe pickle load yielded root code execution on the ECS Fargate-hosted service; from there the researcher extracted container AWS credentials, two GCP service accounts, and every secret in the account.
- The dev-environment target sat under the event's special wildcard scope with a 20% bounty bonus; the author notes the payout was lower than expected.
- All credentials were masked and long since rotated.
A rare, detailed RCE-to-cloud-takeover playbook from a sanctioned event.
More from Infra
- OpenRouter inference providers slash GLM 5.3 output price from $4.40 to $1.61 in a month — AccBalanced · 2026-09-29
- ASCI Q supercomputer crashed every 6.5 hours until a neutron beam exposed cosmic rays as the culprit — lauriewired · 2026-09-29
- Dual 5070+5060Ti local LLM setup too slow: is a single RX 7900XTX the fix? — rawdikrik · 2026-09-29
- How SNI actually works: the TLS feature powering CDNs and multi-tenant routing — HankYeomans · 2026-09-29
- Well-known compute broker joins Compute Exchange as senior deals lead — ns123abc · 2026-09-29
- Google Cloud GA's Memorystore for Valkey 9.1 With 3x the QPS of Its Managed Redis — rseroter · 2026-09-29