Enclave (enclave-vm) prior to 2.7.0 contains a sandbox escape in its JavaScript isolation boundary. When a tool invocation fails, enclave-vm exposes a host-side Error object to untrusted sandboxed JavaScript. Because the Error object retains the host realm’s prototype chain, sandboxed code can traverse the prototype chain to reach the host Function constructor. An attacker can intentionally trigger a host error to obtain this Error object, then use the host Function constructor to compile and execute arbitrary JavaScript in the host Node.js runtime context, bypassing the sandbox’s isolation guarantees.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This is a small standalone proof-of-concept repository containing one Python 3 payload generator, a README, and an MIT license. It is not a Metasploit, Nuclei, or other exploit-framework module. CVE-2026-22686-PoC.py provides French/English interactive and command-line modes, accepts -c/--command for command execution or --revshell LHOST LPORT for a reverse shell, validates the callback port, and can emit raw JavaScript suitable for redirection or copy/paste. The generated payload targets enclave-vm versions earlier than 2.7.0. It triggers a failed callTool invocation, uses the leaked host Error object's prototype chain to reach the host Function constructor, then executes code in the Node.js host context. The resulting host-side code accesses child_process to run a shell command or establish an outbound shell. Property names including constructor, __proto__, __lookupGetter__, and prototype are represented as ASCII code arrays and decoded at runtime. No fixed victim URL, domain, or IP is embedded in the exploit; the only network destination is the operator-controlled reverse-shell LHOST:LPORT.
Repository contains a single Python PoC generator (CVE-2026-22686-PoC.py), a README explaining the ESM/Node.js module-loading bypass, and an MIT license. Core capability: the Python script asks for an OS command and outputs a JavaScript payload intended to be pasted into a vulnerable JavaScript sandbox interpreter affected by CVE-2026-22686. The generated JS payload uses a sandbox-escape pattern: it triggers a host-side exception via callTool('NONEXISTENT', {}), then walks prototypes to obtain the host Function constructor (errProto.constructor.constructor). It then evaluates a constructed string that calls process.getBuiltinModule('child_process').execSync('<cmd>').toString(), achieving OS command execution and printing the result via output(). Targeting/assumptions: the README focuses on Node.js ESM environments ("type": "module"), where require/import are restricted. It highlights process.getBuiltinModule (Node.js >= 22.3.0) as the key post-escape primitive to access built-in modules without require/import. No hardcoded C2, IPs, or network callbacks are present; the only external references are documentation/source links and an image URL.
Repository purpose: a self-contained Node.js web demo/PoC for CVE-2026-22686 ("Host Error" sandbox escape) showing how leaking a host-realm Error object into a vm sandbox allows reaching the host Function constructor and executing arbitrary code. Key components: - web-server.js: Minimal HTTP server exposing a browser UI and a POST /execute endpoint. It runs user-supplied JavaScript inside a sandbox created by ./enclave-vm, captures console output, and returns results as JSON. It binds to 0.0.0.0:3000 and enables permissive CORS. - enclave-vm.js: Mock vulnerable "enclave-vm" implementation. Core bug: when a tool handler throws, the host Error is re-thrown directly into the sandbox (no realm isolation), preserving the host prototype chain. - exploit.js: Working exploit (Vector 35). It intentionally triggers a tool failure (useTool("NONEXISTENT_TOOL")) to catch a host Error, walks prototypes to obtain the host Function constructor, evaluates "return process" to get Node's process object, then uses proc.mainModule.require to load child_process and fs, executes id/whoami, and writes /tmp/pwned.txt. - Dockerfile.web + docker-compose.yml: Containerized deployment of the vulnerable web app on port 3000 for easy reproduction. - README.md: Usage instructions and an inline exploit explanation. Overall exploit capability: remote attacker can submit JavaScript to /execute, escape the intended sandbox boundary via leaked host Error objects, and achieve host-level Node.js RCE (command execution and filesystem write) within the container/host context where the server runs.
Repository purpose: a CTF-style proof-of-concept demonstrating a JavaScript sandbox escape against an `enclave-vm`-based environment by leveraging a host-thrown Error object to reach the host `Function` constructor. Structure: - `README.md`: describes the “Enclave VM Sandbox Escape” challenge. - `package.json` / `package-lock.json`: Node project pinned to `enclave-vm@2.6.0` and its parser/AST dependencies. - `challenge.js` (stub) and `sandbox.js` (stub): intended runner and vulnerable sandbox implementation (not included in detail in provided content). - `poc.js`: the core exploit PoC. - `solution.md`: brief statement of the technique (prototype chain escape via host Error object). Exploit capabilities (from `poc.js`): - Triggers a host-side exception by calling a non-existent tool via `await callTool('THIS_TOOL_DOES_NOT_EXIST_XYZ', {})`. - Captures the resulting host Error object (`hostError = e`). - Uses `Object.prototype.__lookupGetter__('__proto__')` to obtain a native getter for `__proto__`, then calls it on the host Error to retrieve its prototype (`errProto`). - Walks the prototype chain to obtain constructors: `ErrorCtor = errProto.constructor`, then `HostFunc = ErrorCtor.constructor` (i.e., the host `Function` constructor). - Executes host-context code by creating a new function from a string (`HostFunc('return process.env')`) and invoking it, returning host environment variables. Notable implementation details: - Strings like `constructor`, `__proto__`, and `__lookupGetter__` are built via `String.fromCharCode(...)` to evade naive keyword filters. - The PoC demonstrates data exfiltration (`process.env`) but implies broader host code execution if other globals (e.g., `require`, filesystem, network) are reachable in the host context. Network/endpoint observables: - No C2 or attacker-controlled network endpoints are present in the exploit logic. - Only NPM registry tarball URLs appear in `package-lock.json` as dependency sources.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.