mongo-express 0.53.0 without a login, vulnerable to CVE-2019-10758: the /checkValid endpoint parses the document parameter with toBSON, which evaluates it as JavaScript in a vm context that escapes to child_process.
Not startedDockercommit 6fcdf18x86_64 · aarch64Secret
Exploit CVE-2019-10758 to run commands on the mongo-express server and get a shell.
The brief for this lab lives in its repository.