# CVE-2026-34156

## Summary

- **CVE ID:** CVE-2026-34156
- **Severity:** CRITICAL
- **CVSS Score:** 10 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
- **CWE:** CWE-913
- **Published:** Mar 31, 2026
- **Last Modified:** Apr 2, 2026

## Description

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.28, NocoBase's Workflow Script Node executes user-supplied JavaScript inside a Node.js vm sandbox with a custom require allowlist (controlled by WORKFLOW_SCRIPT_MODULES env var). However, the console object passed into the sandbox context exposes host-realm WritableWorkerStdio stream objects via console._stdout and console._stderr. An authenticated attacker can traverse the prototype chain to escape the sandbox and achieve Remote Code Execution as root. This issue has been patched in version 2.0.28.

## Affected Products

- nocobase — nocobase (< 2.0.28)

## References

- [CNA](https://github.com/nocobase/nocobase/security/advisories/GHSA-px3p-vgh9-m57c)
- [CNA](https://github.com/nocobase/nocobase/pull/8967)
- [CNA](https://github.com/nocobase/nocobase/releases/tag/v2.0.28)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 34.97%
- **EPSS Percentile:** 98.3

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._