HTB-Kobold
Kobold is a Linux machine centred around a recently disclosed vulnerability (CVE-2026-23744) in MCPJam, an open-source Model Context Protocol server. Initial access is gained through unauthenticated remote code execution via the MCP connect endpoint. Privilege escalation abuses Docker group membership to mount the host filesystem and read the root flag.