CVE-2026-48546
HIGHKanaDojo < 0.1.18 Sandbox Escape RCE via messages.cjs
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2026-48546. PoCs published by ghapvharmo.
AI-analyzed exploit summary This repository contains a functional proof-of-concept for CVE-2026-48546, demonstrating a race condition in the progress-sync API endpoint that could lead to unauthorized data overwrites or stale data acceptance. The vulnerability arises from improper atomicity in the Lua script handling concurrent updates.
Description
KanaDojo before 0.1.18 contains a sandbox escape vulnerability that allows an attacker to execute arbitrary code by exploiting the explicit passing of the global require function into a Node.js vm.runInNewContext() sandbox context in the issue-auto-respond.yml workflow. Attackers can submit a pull request modifying messages.cjs to import arbitrary Node.js modules, bypassing sandbox restrictions and achieving remote code execution with full GitHub Actions runner privileges including access to AUTOMATION_PR_TOKEN.
Exploits (1)
This repository contains a functional proof-of-concept for CVE-2026-48546, demonstrating a race condition in the progress-sync API endpoint that could lead to unauthorized data overwrites or stale data acceptance. The vulnerability arises from improper atomicity in the Lua script handling concurrent updates.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N