HackTheBox - Forge

Bypass SSRF filters using domain redirection and abusing Python PDB

HackTheBox - Nunchucks

SSTI in Nunjucks and SUID capability on Perl