logo

NocoBase Critical Alert: Sandbox Escape Grants Attackers Root Access

ID: 0de595e4-5717-535c-bd87-bc45f1c202a8

STIX ID: report--0de595e4-5717-535c-bd87-bc45f1c202a8

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-04-01

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical vulnerability (CVE-2026-34156, CVSS 10.0) in NocoBase’s Workflow Script Node allows authenticated users to escape the Node.js vm sandbox by exposing the host console object, enabling prototype chain traversal to the host Function constructor. Successful exploitation yields root RCE in containers, theft of environment credentials, arbitrary file system access via require('fs'), and potential lateral movement; NocoBase released a patch (2.0.28) and the report recommends replacing vm with isolated-vm, proxying console objects, and running containers non-root.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.