
Nice box. A bit disappointing that Ajenti service is running by root user and you don’t have privesc flow. Reverse shell can be done but not necessary.
However I spend 1 day to figure out the curl sintaxy but time was a benefit because I also discovered the postman tool. Thumb up anyway for the JWT approache, it’s not very spread along the developers but industries such as banking are starting to use it.