PoC Archive PoC Archive

tag

Sandbox-Escape

Node.js Permission Model Symlink Escape (CVE-2025-55130)
CVE-2025-55130 binary Unverified
CVE-2025-55130binaryCRITICAL 9.1Unverified2026-09-03Firefox SpiderMonkey JIT Type Confusion (CVE-2026-10702)
CVE-2026-10702 binary Unverified
CVE-2026-10702binaryMEDIUM 4.3Unverified2026-09-03Crawl4AI JsonCssExtractionStrategy AST Sandbox Escape → Unauthenticated RCE (CVE-2026-53753)
CVE-2026-53753 (GHSA-qxjp-w3pj-48m7) web Patched
CVE-2026-53753webCRITICAL 9.8Patched2026-07-27Typebot Unauthenticated Preview-Chat SSRF — CVE-2026-33712
CVE-2026-33712 web Patched
CVE-2026-33712webHIGHPatched2026-07-05n8n HTTP Request Node Pagination Prototype Pollution → Remote Code Execution (CVE-2026-44789)
CVE-2026-44789 / GHSA-c8xv-5998-g76h web Patched
CVE-2026-44789 / GHSA-c8xv-5998-g76hwebCRITICAL 9.4Patched2026-07-05LiteLLM Guardrail Custom-Code Sandbox Escape to Root RCE (CVE-2026-40217) EPSS 15%
CVE-2026-40217 (X41-2026-001, GHSA-3926-2jvf-fg29) web Patched
CVE-2026-40217webCRITICAL 8.8Patched2026-07-05Jinjava Server-Side Template Injection to RCE via Jackson ObjectMapper (CVE-2026-25526)
CVE-2026-25526 web Patched
CVE-2026-25526webCRITICALPatched2026-07-05iOS App Intents Path Traversal — CVE-2026-28995
CVE-2026-28995 misc Patched
CVE-2026-28995miscHIGHPatched2026-07-05Adobe Acrobat/Reader PDF Exploit Generator — Claimed Prototype Pollution (CVE-2026-3462)
CVE-2026-3462 (repo internally references CVE-2026-34621 — CVE-ID mismatch, see Notes) misc Patched
CVE-2026-3462miscCRITICALPatched2026-07-05Lunar Client Modrinth Explore Raw-HTML to Local Launcher Execution Chain
None assigned as of 2026-07-03 binary Unverified
None assigned as of 2026-07-03binaryCRITICAL 3.1Unverified2026-07-03Ladybird Browser WebAssembly ESM Host-Function Use-After-Free RCE
None assigned as of 2026-07-03 web Unverified
None assigned as of 2026-07-03webCRITICALUnverified2026-07-03Adobe Acrobat/Reader Prototype Pollution Sandbox Escape (CVE-2026-34621) KEV
CVE-2026-34621 binary Unverified
CVE-2026-34621binaryCRITICAL 9.8Unverified2026-05-16