BRIEFING NOTE - CVE-2026-6224 A sandbox bypass vulnerability has been identified in NocoDB's plugin-workflow-javascript component, specifically within the createSafeConsole function of the Vm.js file. The flaw affects all versions up to and including 2.0.23, allowing attackers to escape the intended sandbox restrictions through code manipulation. The vulnerability carries a CVSS score of 7.3 (HIGH) with a network-based attack vector requiring no authentication or user interaction. The attack presents low complexity and could result in partial compromise of confidentiality, integrity, and availability. The EPSS score of 0.0005 indicates relatively low predicted exploitation probability across the vulnerability landscape. The exploit code has been publicly released and is available for potential attackers. However, the vulnerability currently shows no evidence of active exploitation in the wild, with no entries on known exploited vulnerabilities lists. The vendor was notified early in the disclosure process but has not provided a response or patch, leaving affected organizations without an official remediation path and increasing reliance on defensive measures or version upgrades.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Nocobase | Plugin-Workflow-Javascript | 2.0.0, 2.0.1, 2.0.10, 2.0.11, 2.0.12, 2.0.13, 2.0.14, 2.0.15, 2.0.16, 2.0.17, 2.0.18, 2.0.19, 2.0.2, 2.0.20, 2.0.21, 2.0.22, 2.0.23, 2.0.3, 2.0.4, 2.0.5, 2.0.6, 2.0.7, 2.0.8, 2.0.9CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.