<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Sandbox-Escape — PoC Archive</title><link>https://poc.intelseclab.com/tags/sandbox-escape/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 27 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/sandbox-escape/index.xml" rel="self" type="application/rss+xml"/><item><title>Crawl4AI JsonCssExtractionStrategy AST Sandbox Escape → Unauthenticated RCE (CVE-2026-53753)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-53753-crawl4ai-sandbox-escape-rce/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-53753-crawl4ai-sandbox-escape-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-53753 (GHSA-qxjp-w3pj-48m7). Status: Weaponized — full end-to-end command execution reproduced against the official unclecode/crawl4ai:0.8.6 image. Affects: Crawl4AI — open-source LLM-friendly web crawler/scraper, Docker API server. Tags: crawl4ai, sandbox-escape, rce, python, ast-bypass, unauthenticated, llm-tooling, ai-security.</description><category>web</category><category>Critical</category><category>crawl4ai</category><category>sandbox-escape</category><category>rce</category><category>python</category><category>ast-bypass</category><category>unauthenticated</category><category>llm-tooling</category><category>ai-security</category></item><item><title>Typebot Unauthenticated Preview-Chat SSRF — CVE-2026-33712</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33712-typebot-ssrf/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33712-typebot-ssrf/</guid><description>High severity — web · CVE-2026-33712. Status: PoC. Affects: Typebot (open-source chatbot builder), preview chat endpoint. Tags: ssrf, typebot, isolated-vm, sandbox-escape, cloud-metadata, node-js, unauthenticated, chatbot.</description><category>web</category><category>High</category><category>ssrf</category><category>typebot</category><category>isolated-vm</category><category>sandbox-escape</category><category>cloud-metadata</category><category>node-js</category><category>unauthenticated</category><category>chatbot</category></item><item><title>n8n HTTP Request Node Pagination Prototype Pollution → Remote Code Execution (CVE-2026-44789)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-44789-n8n-prototype-pollution-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-44789-n8n-prototype-pollution-rce/</guid><description>Critical severity (CVSS 9.4) — web · CVE-2026-44789 / GHSA-c8xv-5998-g76h. Status: PoC. Affects: n8n (workflow automation platform). Tags: n8n, prototype-pollution, rce, node-options, sandbox-escape, task-runner, workflow-automation.</description><category>web</category><category>Critical</category><category>n8n</category><category>prototype-pollution</category><category>rce</category><category>node-options</category><category>sandbox-escape</category><category>task-runner</category><category>workflow-automation</category></item><item><title>LiteLLM Guardrail Custom-Code Sandbox Escape to Root RCE (CVE-2026-40217)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-40217-litellm-guardrail-sandbox-escape/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-40217-litellm-guardrail-sandbox-escape/</guid><description>Critical severity (CVSS 8.8) — web · CVE-2026-40217 (X41-2026-001, GHSA-3926-2jvf-fg29). Status: PoC. Affects: LiteLLM (open-source LLM proxy/gateway), POST /guardrails/test_custom_code endpoint. Tags: litellm, llm-proxy, sandbox-escape, bytecode-manipulation, cwe-913, docker, root-rce, authenticated.</description><category>web</category><category>Critical</category><category>litellm</category><category>llm-proxy</category><category>sandbox-escape</category><category>bytecode-manipulation</category><category>cwe-913</category><category>docker</category><category>root-rce</category><category>authenticated</category></item><item><title>Jinjava Server-Side Template Injection to RCE via Jackson ObjectMapper (CVE-2026-25526)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-25526-jinjava-ssti-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-25526-jinjava-ssti-rce/</guid><description>Critical severity — web · CVE-2026-25526. Status: Weaponized. Affects: Jinjava (HubSpot's Java Jinja-like template engine). Tags: ssti, jinjava, java, jackson, objectmapper, sandbox-escape, rce, deserialization.</description><category>web</category><category>Critical</category><category>ssti</category><category>jinjava</category><category>java</category><category>jackson</category><category>objectmapper</category><category>sandbox-escape</category><category>rce</category><category>deserialization</category></item><item><title>iOS App Intents Path Traversal — CVE-2026-28995</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-28995-ios-appintents-path-traversal/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-28995-ios-appintents-path-traversal/</guid><description>High severity — misc · CVE-2026-28995. Status: PoC. Affects: Apple App Intents framework (iOS). Tags: ios, app-intents, path-traversal, sandbox-escape, swift, file-disclosure, mobile.</description><category>misc</category><category>High</category><category>ios</category><category>app-intents</category><category>path-traversal</category><category>sandbox-escape</category><category>swift</category><category>file-disclosure</category><category>mobile</category></item><item><title>Adobe Acrobat/Reader PDF Exploit Generator — Claimed Prototype Pollution (CVE-2026-3462)</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-3462-acrobat-pdf-exploit-generator/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-3462-acrobat-pdf-exploit-generator/</guid><description>Critical severity — misc · CVE-2026-3462 (repo internally references CVE-2026-34621 — CVE-ID mismatch, see Notes). Status: Weaponized. Affects: Adobe Acrobat / Acrobat Reader (DC Continuous and 2024 Classic tracks). Tags: pdf, exploit-generator, prototype-pollution, sandbox-escape, evasion, persistence, malware-generator, farmed-repo-suspected.</description><category>misc</category><category>Critical</category><category>pdf</category><category>exploit-generator</category><category>prototype-pollution</category><category>sandbox-escape</category><category>evasion</category><category>persistence</category><category>malware-generator</category><category>farmed-repo-suspected</category></item><item><title>Lunar Client Modrinth Explore Raw-HTML to Local Launcher Execution Chain</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-03_lunar-client-modrinth-rce-chain/</link><pubDate>Fri, 03 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-03_lunar-client-modrinth-rce-chain/</guid><description>Critical severity (CVSS 3.1) — binary · None assigned as of 2026-07-03. Status: Incomplete PoC. Affects: Lunar Client (Electron desktop application), Modrinth Explore integration. Tags: lunar-client, electron, minecraft, modrinth, raw-html-injection, ipc, rce, sandbox-escape, launcher-abuse.</description><category>binary</category><category>Critical</category><category>lunar-client</category><category>electron</category><category>minecraft</category><category>modrinth</category><category>raw-html-injection</category><category>ipc</category><category>rce</category><category>sandbox-escape</category><category>launcher-abuse</category></item><item><title>Ladybird Browser WebAssembly ESM Host-Function Use-After-Free RCE</title><link>https://poc.intelseclab.com/pocs/web/2026-07-03_ladybird-wasm-esm-host-function-rce/</link><pubDate>Fri, 03 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-03_ladybird-wasm-esm-host-function-rce/</guid><description>Critical severity — web · None assigned as of 2026-07-03. Status: Weaponized. Affects: Ladybird web browser (WebContent process, LibWeb / LibWasm). Tags: ladybird, browser, webassembly, wasm-gc, use-after-free, memory-corruption, rce, javascript-engine, sandbox-escape.</description><category>web</category><category>Critical</category><category>ladybird</category><category>browser</category><category>webassembly</category><category>wasm-gc</category><category>use-after-free</category><category>memory-corruption</category><category>rce</category><category>javascript-engine</category><category>sandbox-escape</category></item><item><title>Adobe Acrobat/Reader Prototype Pollution Sandbox Escape (CVE-2026-34621)</title><link>https://poc.intelseclab.com/pocs/binary/2026-05-16_adobe-acrobat-prototype-pollution-sandbox-escape/</link><pubDate>Sat, 16 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-05-16_adobe-acrobat-prototype-pollution-sandbox-escape/</guid><description>Critical severity (CVSS 9.8) — binary · CVE-2026-34621. Status: Weaponized. Affects: Adobe Acrobat DC / Adobe Acrobat Reader DC / Adobe Acrobat 2024 JavaScript engine sandbox boundary. Tags: prototype-pollution, sandbox-escape, Adobe-Acrobat, Adobe-Reader, PDF, RCE, Windows, macOS, user-interaction.</description><category>binary</category><category>Critical</category><category>prototype-pollution</category><category>sandbox-escape</category><category>Adobe-Acrobat</category><category>Adobe-Reader</category><category>PDF</category><category>RCE</category><category>Windows</category><category>macOS</category><category>user-interaction</category></item></channel></rss>