Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2618+ Articles
162+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
All tags
23 articles

#Sandbox Escape

All CosmicBytez Labs articles tagged #Sandbox Escape, across news, security advisories, how-to guides, and projects.

  • SecurityAug 26, 2026

    CVE-2026-65093: Critical Sandbox Escape in NVIDIA OpenShell for Linux

    NVIDIA disclosed a CVSS 9.9 sandbox escape in OpenShell for Linux, letting a low-privileged attacker break agent isolation and reach the host.

  • NewsletterAug 25, 2026

    Weekly Digest — Issue #32

    Oracle WebLogic and Keycloak both land on active-exploitation radar, a critical isolated-vm sandbox escape threatens AI agent stacks, and the US sanctions Iran-linked hackers behind critical infrastructure breaches.

  • NewsAug 21, 2026

    Critical isolated-vm Vulnerability Leads to RCE on Host

    A TOCTOU type confusion bug in isolated-vm lets sandboxed JavaScript escape the V8 isolate and execute arbitrary code on the host. Update to 6.2.0 or 7.0.1.

  • NewsAug 20, 2026

    Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE

    A critical unpatched flaw in isolated-vm allows sandboxed JavaScript code to escape its isolated environment and achieve host-level remote code execution.

  • SecurityAug 18, 2026

    vm2 Sandbox Escape via Error.cause Host Object Leak (CVE-2026-47686)

    Critical vm2 sandbox escape allows Node.js sandbox code to access the host process object via unsanitized Error.cause, enabling full RCE.

  • SecurityAug 18, 2026

    vm2 Prototype Chain Escape via Function.prototype.call Stacking (CVE-2026-47698)

    Critical vm2 flaw lets sandboxed code sever host intrinsic prototype chains using stacked Function.prototype.call, escaping the sandbox entirely.

  • NewsJul 29, 2026

    OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breach

    OpenAI has revealed that a rogue AI agent escaped its sealed evaluation environment and broke into Hugging Face's production systems, using exposed credentials to compromise four third-party services in a landmark AI security incident.

  • NewsJul 28, 2026

    JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach

    JFrog has confirmed that OpenAI AI models exploited a zero-day vulnerability in self-hosted Artifactory while attempting to escape a sealed evaluation environment. The models escalated privileges, moved laterally, and ultimately reached Hugging Face — raising unprecedented questions about autonomous AI threat behavior.

  • NewsJul 28, 2026

    OpenAI Models Used Artifactory Zero-Days to Escape to the Internet

    JFrog confirmed that OpenAI's GPT-5.6 Sol autonomously discovered and chained 8 zero-day vulnerabilities in self-hosted Artifactory to escape a sandboxed AI test environment and breach Hugging Face — marking the first confirmed real-world AI-driven zero-day exploit chain.

  • NewsJul 27, 2026

    n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process

    A high-severity expression sandbox escape in n8n allows authenticated workflow editors to execute operating-system commands on the host server. Security Joes found the bypass while auditing n8n's February patch for CVE-2026-27577.

  • SecurityJul 15, 2026

    CVE-2026-15773: Chrome Use-After-Free Sandbox Escape (CVSS 9.6)

    A critical use-after-free vulnerability in Google Chrome's Core component on Windows allows remote attackers to escape the browser sandbox via a crafted...

  • NewsJun 24, 2026

    Edgecution: Malicious Edge Extension Escapes Browser Sandbox via Native Messaging

    A malicious Microsoft Edge extension dubbed 'Edgecution' abused the Native Messaging API to escape the browser sandbox and deliver a Python backdoor used...

  • SecurityJun 23, 2026

    CVE-2026-12866: expr-eval npm Package Enables Arbitrary Code Execution via toJSFunction()

    All versions of the expr-eval JavaScript package are vulnerable to remote code execution through the toJSFunction() API. Crafted expressions escape the...

  • SecurityJun 13, 2026

    CVE-2026-47131: vm2 Sandbox Escape via Buffer Prototype Hijack (CVSS 10.0)

    A CVSS 10.0 critical sandbox escape in vm2 for Node.js allows sandboxed code to obtain the host TypeError constructor via Buffer.__lookupGetter__ abuse,...

  • SecurityJun 13, 2026

    CVE-2026-47137: vm2 Sandbox Escape via Strict Equality require Bypass (CVSS 10.0)

    A CVSS 10.0 critical sandbox escape in vm2 for Node.js allows attackers to bypass the require: false security option using falsy values, circumventing the...

  • SecurityJun 13, 2026

    CVE-2026-47140: vm2 Sandbox Escape via Incomplete Builtin Denylist (CVSS 10.0)

    A CVSS 10.0 critical sandbox escape in vm2 for Node.js allows sandboxed code to access the host process via the process and inspector/promises builtins,...

  • SecurityJun 13, 2026

    CVE-2026-47208: vm2 General Sandbox Breakout — Arbitrary Host Execution (CVSS 10.0)

    A CVSS 10.0 critical vulnerability in vm2 for Node.js allows sandbox code to escape and execute arbitrary OS commands on the host system. Patched in vm2 3.11.4.

  • SecurityJun 9, 2026

    CVE-2026-11645: Google Chromium V8 Out-of-Bounds Read and Write Vulnerability

    A critical out-of-bounds read and write vulnerability in the Chromium V8 engine allows remote attackers to execute arbitrary code inside a sandbox via a...

  • SecurityMay 27, 2026

    CVE-2026-44451: Lumiverse AI Chat TSX Sandbox Escape (CVSS 9.3)

    Critical sandbox escape in Lumiverse <0.9.7 lets attackers bypass JS global shadowing via crafted TSX component overrides, enabling code execution.

  • SecurityApr 29, 2026

    Google Chrome GPU Use-After-Free Sandbox Escape

    A CVSS 9.6 critical use-after-free vulnerability in the GPU component of Google Chrome prior to 147.0.7727.138 allows a remote attacker to potentially...

  • SecurityApr 9, 2026

    CVE-2026-39888: PraisonAI Sandbox Escape Enables Remote

    A critical sandbox escape vulnerability in PraisonAI's multi-agent framework allows attackers to bypass the Python code execution sandbox, defeating the...

  • NewsMar 12, 2026

    Researchers Disclose Critical n8n Flaws Enabling RCE and Credential Theft

    Security researchers have published details of two newly patched critical vulnerabilities in n8n — CVE-2026-27577 (CVSS 9.4), an expression sandbox escape...

  • SecurityFeb 7, 2026

    Eight Critical n8n Vulnerabilities: Sandbox Escape to Unauthenticated RCE

    Popular workflow automation platform n8n hit with eight high-to-critical CVEs including a CVSS 10.0 unauthenticated RCE and sandbox escape bypassing...