CVE-2026-34156 is a sandbox-escape vulnerability in the NocoBase Workflow Script Node before version 2.0.28. The node executes user-supplied JavaScript in a Node.js vm sandbox and restricts module loading through a custom allowlist controlled by the WORKFLOW_SCRIPT_MODULES environment variable. However, the sandbox receives a console object whose _stdout and _stderr properties expose host-realm WritableWorkerStdio stream objects. An authenticated attacker can traverse the exposed objects' prototype chain to escape the sandbox and execute code as root.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository is a small standalone Python proof-of-concept exploit for CVE-2026-34156 affecting NocoBase workflow Script Nodes. The repo contains only two files: a single executable Python script (`CVE-2026-34156.py`) and a README with vulnerability description and installation notes. The Python script is the clear entry point and implements the full exploit flow. Exploit structure: the script parses CLI arguments for target URL, credentials, a command, or a reverse-shell callback. It authenticates to the target NocoBase instance using `POST /api/auth:signIn`, extracts a bearer token from the JSON response, and then sends a crafted Script Node payload to `POST /api/flow_nodes:test`. The malicious payload is JavaScript intended to run inside the workflow engine sandbox. It abuses `console._stdout.constructor.constructor("return process")()` to recover the Node.js `process` object, then loads `child_process` and executes attacker-controlled shell commands via `execSync`. Main capabilities: authenticated remote command execution, retrieval of command output through the HTTP response, and optional reverse shell delivery using bash over `/dev/tcp/<ip>/<port>`. The exploit is operational rather than a mere detector because it performs authentication, payload generation, and exploit delivery end-to-end. It is not framework-based and does not include advanced automation beyond basic API interaction. Targeting: the repository explicitly targets NocoBase and claims vulnerable versions below 2.0.28, while the README specifically mentions <= 2.0.26. Successful exploitation requires valid credentials and sufficient permissions to create or test workflow Script Nodes. The attack vector is authenticated web/network access to the NocoBase API. The overall purpose of the repository is to demonstrate sandbox escape leading to root-level RCE inside the NocoBase container/host context, depending on how the service is deployed.
Small standalone Python PoC repository for CVE-2026-34156 affecting NocoBase <= 2.0.27. The repository contains one executable exploit script (exploit.py) plus a README and basic git metadata files. The exploit is not part of a larger framework. Core capability: the script authenticates to NocoBase using supplied or default credentials, obtains a JWT from /api/auth:signIn, then sends a crafted JSON request to /api/flow_nodes:test to execute attacker-controlled JavaScript in the workflow script node. The JavaScript payload abuses console._stdout.constructor.constructor to recover the host Function constructor, returns the real process object, requires child_process, and runs arbitrary shell commands via execSync('/bin/sh'). Command output is returned through the API response and printed locally. Operational flow in exploit.py: - build_payload(cmd): constructs the malicious JavaScript sandbox-escape payload. - login(target, username, password): POSTs credentials to the sign-in endpoint and extracts the JWT token. - exploit_cmd(target, token, cmd): POSTs the malicious workflow script definition to the vulnerable test endpoint and prints returned command output. - interactive_shell(target, token): loops over user input to provide repeated command execution. - main(): parses CLI arguments, authenticates, performs an initial 'id' execution check, then either runs a single command or enters interactive mode. The exploit supports both one-shot command execution and an interactive pseudo-shell, making it more than a simple detector. It assumes authenticated access and a vulnerable NocoBase deployment where the workflow script test endpoint is reachable and permitted for the user. Default credentials are hardcoded as admin@nocobase.com / admin123 for convenience, but custom credentials can be supplied.
Repository contains a small exploit package for CVE-2026-34156 affecting NocoBase versions before 2.0.28. There are three files: a Python PoC exploit, a Nuclei YAML template, and a README. Because the repository includes a Nuclei template, it can be considered framework-related, but the repository also contains standalone exploit code. The main exploit capability is authenticated remote code execution through a sandbox escape in the NocoBase Workflow JavaScript Script Node. The Python script logs into the target using /api/auth/signin, then submits a crafted workflow object to /api/flow_nodes:test. The embedded JavaScript payload abuses console._stdout.constructor.constructor('return process')() to recover the real Node.js process object, then loads child_process and executes attacker-supplied commands with execSync. The script supports either single-command execution or a hardcoded bash reverse shell using /dev/tcp/IP/PORT. This makes the exploit operational rather than a simple proof-of-concept. The Nuclei template is a detection-oriented companion that sends a similar malicious script to /api/flow_nodes:test, but instead of a shell it executes an echo command with a unique marker and matches that marker in the response body. That file is intended for safe-ish vulnerability confirmation rather than post-exploitation. Fingerprintable endpoints are limited and centered on the target web application: /api/auth/signin for login and /api/flow_nodes:test for script-node execution/testing. Additional observables include the reverse-shell pseudo-path /dev/tcp/IP/PORT and several documentation/reference URLs. Overall, the repository’s purpose is to demonstrate and validate exploitation of a NocoBase workflow sandbox escape leading to arbitrary command execution, potentially as root inside the application container.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A CVE record whose template CVSS score metadata was being corrected to agree with its CVSS metrics vector and NVD's computed score.
Unknown
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.