BRIEFING NOTE CVE-2026-6878 affects ByteDance verl versions up to 0.7.0 and involves a sandbox bypass vulnerability in the math_equal function within prime_math/grader.py. This flaw allows attackers to escape the intended sandboxed environment, potentially compromising system integrity and data confidentiality. The vulnerability has a CVSS 3.1 score of 5.6 (MEDIUM severity) with a network-based attack vector that requires high complexity and no user interaction. The attack can result in limited impacts to confidentiality, integrity, and availability of the affected system. While exploitability is classified as difficult, a public exploit is available, elevating practical risk. The vulnerability is currently listed on CISA's KEV catalog as actively exploited in the wild, indicating real-world attack activity. Despite early vendor notification, ByteDance has not provided a response or patch, leaving users without official mitigation. Organizations running affected verl versions should prioritize evaluation of the public exploit and consider implementing compensating controls or version upgrades when available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| ByteDance | Verl | 0.1, 0.2, 0.3, 0.4, 0.5, 0.6, 0.7.0CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.