8.5
/ 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Description
KanaDojo before 0.1.18 contains a sandbox escape vulnerability that allows an attacker to execute arbitrary code by exploiting the explicit passing of the global require function into a Node.js vm.runInNewContext() sandbox context in the issue-auto-respond.yml workflow. Attackers can submit a pull request modifying messages.cjs to import arbitrary Node.js modules, bypassing sandbox restrictions and achieving remote code execution with full GitHub Actions runner privileges including access to AUTOMATION_PR_TOKEN.
AI Analysis
Sandbox escape vulnerability allowing remote code execution with full GitHub Actions runner privileges
Basic Information
ID
CVE-2026-48546
Source
VulnCheck
Published
Jun 11, 2026 at 17:53
Modified
Jun 11, 2026 at 18:50
Affected Product
Vendor
lingdojo
Product
kana-dojo
Affected Versions
lingdojo kana-dojo 0
CWE Classification
AI Assessment
AI Score
8.5 / 10
AI Severity
High
Vendor
LingDojo
Product
KanaDojo
Version
0.1.17 and earlier