EIP-2026-102885

PRE-CVE

JRuby Sandbox 0.2.2 - Sandbox Escape

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-102885. PoCs published by joernchen.

AI-analyzed exploit summary This exploit demonstrates a sandbox escape in jruby-sandbox <= 0.2.2 by importing Java classes to execute arbitrary commands outside the sandboxed environment. It leverages Java's ProcessBuilder to spawn a shell and execute the 'id' command.

Description

JRuby Sandbox 0.2.2 - Sandbox Escape

Exploits (1)

exploitdb WORKING POC
by joernchen · textlocallinux
https://www.exploit-db.com/exploits/33028

This exploit demonstrates a sandbox escape in jruby-sandbox <= 0.2.2 by importing Java classes to execute arbitrary commands outside the sandboxed environment. It leverages Java's ProcessBuilder to spawn a shell and execute the 'id' command.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: jruby-sandbox <= 0.2.2
No auth needed
Prerequisites: Access to a system running jruby-sandbox <= 0.2.2
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026