Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-6878

20
FAUCET Score

BRIEFING NOTE CVE-2026-6878 affects ByteDance verl versions up to 0.7.0 and involves a sandbox bypass vulnerability in the math_equal function within prime_math/grader.py. This flaw allows attackers to escape the intended sandboxed environment, potentially compromising system integrity and data confidentiality. The vulnerability has a CVSS 3.1 score of 5.6 (MEDIUM severity) with a network-based attack vector that requires high complexity and no user interaction. The attack can result in limited impacts to confidentiality, integrity, and availability of the affected system. While exploitability is classified as difficult, a public exploit is available, elevating practical risk. The vulnerability is currently listed on CISA's KEV catalog as actively exploited in the wild, indicating real-world attack activity. Despite early vendor notification, ByteDance has not provided a response or patch, leaving users without official mitigation. Organizations running affected verl versions should prioritize evaluation of the public exploit and consider implementing compensating controls or version upgrades when available.

Impacted Technologies

VendorProductVersion(s)CPE
ByteDanceVerl
0.1, 0.2, 0.3, 0.4, 0.5, 0.6, 0.7.0CNA affected

CVSS Data

CVSS version used by this source: 4.0

2.9LOW

CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
HIGH
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
LOW
VS Integrity
LOW
VS Availability
LOW
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
PROOF_OF_CONCEPT
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.33%
Probability of exploitation in next 30 days
EPSS Percentile
25.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0033 is in the 3rd percentile among its peer group of 19,955 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

pipGHSA-h57c-v2v3-5v3vlow

verl's math_equal() Vulnerable to Arbitrary Code Execution via Unsafe eval()

Apr 23, 2026

References

github.com / zast-ai/vulnerability-reports/blob/main/bytedance/verl_rce.md
vuldb.com / submit/795257
vuldb.com / vuln/359040
vuldb.com / vuln/359040/cti