PT-2026-48700 · Lingdojo · Kana-Dojo

Katriel Moses

+1

·

Published

2026-06-11

·

Updated

2026-06-11

·

CVE-2026-48546

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
KanaDojo before 0.1.18 contains a sandbox escape vulnerability that allows an attacker to execute arbitrary code by exploiting the explicit passing of the global require function into a Node.js vm.runInNewContext() sandbox context in the issue-auto-respond.yml workflow. Attackers can submit a pull request modifying messages.cjs to import arbitrary Node.js modules, bypassing sandbox restrictions and achieving remote code execution with full GitHub Actions runner privileges including access to AUTOMATION PR TOKEN.

Fix

Protection Mechanism Failure

Weakness Enumeration

Related Identifiers

CVE-2026-48546

Affected Products

Kana-Dojo