CVE-2026-34156Patch(nocobase / nocobase)

HIGHCVSS 9.9 · CRITICAL

Exploitation observed; activity peaked at 10 mentions and remains active

Immediate actions

  • Patch nocobase nocobase systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.28, NocoBase's Workflow Script Node executes user-supplied JavaScript inside a Node.js vm sandbox with a custom require allowlist (controlled by WORKFLOW_SCRIPT_MODULES env var). However, the console object passed into the sandbox context exposes host-realm WritableWorkerStdio stream objects via console._stdout and console._stderr. An authenticated attacker can traverse the prototype chain to escape the sandbox and achieve Remote Code Execution as root. This issue has been patched in version 2.0.28.

7.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-913

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nocobase

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 17 mentions across 5 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 5 signals
  • PoC mentioned or linked in 8 signals
  • Patch or workaround mentioned in 8 signals
  • Technical details provided in 15 signals
  • Disclosure: 3 classified signals
  • Peaked 4d ago at 10 mentions (2026-03-31); latest day: 1
  • 17 total mentions across 5 days

Affected systems

Vendors
Products
nocobase

Deep dive

Activity timeline17 mentions / 5d
035810Mentions · 2026-03-31: 10Mentions · 2026-04-01: 4Mentions · 2026-04-03: 1Mentions · 2026-04-07: 1Mentions · 2026-05-07: 1PoC Mentioned / Linked · 2026-03-31: 3PoC Mentioned / Linked · 2026-04-01: 2PoC Mentioned / Linked · 2026-04-03: 1PoC Mentioned / Linked · 2026-04-07: 1PoC Mentioned / Linked · 2026-05-07: 1Exploit Tool / Code · 2026-03-31: 1Exploit Tool / Code · 2026-04-01: 1Exploit Tool / Code · 2026-04-03: 1Exploit Tool / Code · 2026-04-07: 1Exploit Tool / Code · 2026-05-07: 1Active Exploitation · 2026-03-31: 1Patch / Workaround · 2026-03-31: 3Patch / Workaround · 2026-04-01: 2Patch / Workaround · 2026-04-03: 1Patch / Workaround · 2026-04-07: 1Patch / Workaround · 2026-05-07: 1Technical Details · 2026-03-31: 9Technical Details · 2026-04-01: 3Technical Details · 2026-04-03: 1Technical Details · 2026-04-07: 1Technical Details · 2026-05-07: 103-3104-0104-0304-0705-07
Signal classification6 categories
Patch
423.5%
PoC
423.5%
Disclosure
317.6%
General
317.6%
Exploit
211.8%
Active Exploitation
15.9%
Referenced assets13 URLs
Classification over time
DateTotalLabels
2026-03-3110
Active Exploitation1Disclosure3General2Patch2PoC2
2026-04-014
Exploit1General1Patch2
2026-04-031
PoC1
2026-04-071
PoC1
2026-05-071
Exploit1
Full discourse17 posts
  • Gray Hats@the_yellow_fall
    Patch

    NocoBase patches a CVSS 10.0 RCE vulnerability (CVE-2026-34156). A simple console object bypasses the sandbox for root access. Update to 2.0.28 now! #NocoBase #CyberSecurity #RCE #InfoSec #NodeJS #SandboxEscape #BugBounty #RootAccess #ZeroDay https://securityonline.info/nocobase-critical-rce-sandbox-escape-cve-2026-34156/ https://t.co/vDsXdUsqvw

    Post summary

    The post announces a critical RCE vulnerability in NocoBase (CVE‑2026‑34156) and urges users to update to version 2.0.28 to apply the patch.

    06054562
    12.3K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-34156 - critical 🚨 NocoBase - VM Sandbox Escape to Remote Code Execution > NocoBase Workflow Script Node executes user-supplied JavaScript inside a Node.js vm s... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-34156 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet announces CVE-2026-34156 as a critical NocoBase vulnerability that allows remote code execution via VM sandbox escape, but provides no proof‑of‑concept, exploit code, active exploitation report or patch details.

    00032257
    960 followersView on X
  • Ashraf Zaryouh@0xBlackash
    PoC

    🚨 CVE-2026-34156 - Critical RCE in NocoBase Sandbox escape in Workflow Script Node allows attackers to achieve root execution. Affected: All versions < 2.0.28 → Immediate upgrade to 2.0.28+ recommended PoC + Nuclei template available: https://github.com/0xBlackash/CVE-2026-34156 #NocoBase https://t.co/192TQsicT3

    Post summary

    A critical RCE in NocoBase (CVE-2026-34156) is disclosed with a PoC and Nuclei template, and users are urged to upgrade to version 2.0.28 or later.

    0001298
    4 followersView on X
  • DFIR Radar@DFIR_Radar
    Exploit

    NocoBase workflow engine contains a critical VM sandbox escape (CVE-2026-34156, CVSS 9.9) enabling authenticated users to achieve remote code execution as root via prototype pollution. Technical breakdown: • Vulnerability in Workflow Script Node's JavaScript sandbox implementation • Attack chain: console._stdout.constructor.constructor → host-realm Function → process.mainModule.require('child_process') → RCE • Affects NocoBase <= 2.0.27, patched in 2.0.28 (CWE-913: Improper Control of Dynamically-Managed Code Resources) • Requires valid credentials but any user with workflow access can exploit • Full exploit code available with command execution, credential dumping, and reverse shell capabilities Hunt for NocoBase workflow execution events in application logs and monitor for unusual child_process spawning from Node.js contexts. Check for version 2.0.27 or earlier in your environment. #DFIR_Radar

    Post summary

    NocoBase workflow engine suffers a critical VM sandbox escape (CVE-2026-34156) that permits authenticated users to achieve RCE as root; full exploit code is publicly available, and version 2.0.28 patches the issue.

    10010178
    1.4K followersView on X
  • The Hacker Wire@TheHackerWire
    General

    🔴 CVE-2026-34156 - Critical NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.28, NocoBase's Workflow Script Node executes user-sup... https://www.thehackerwire.com/vulnerability/CVE-2026-34156/ https://t.co/RM4k3CJ6Rq

    Post summary

    CVE-2026-34156 impacts NocoBase's Workflow Script Node before version 2.0.28, likely allowing user‑supplied script execution, but no PoC, exploit, or active exploitation is detailed.

    0101056
    163 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-34156: CRITICAL] NocoBase's prior to version 2.0.28 had a security flaw enabling an attacker to achieve Remote Code Execution. The issue has been resolved in version 2.0.28.#cve,CVE-2026-34156,#cybersecurity https://cvefind.com/CVE-2026-34156

    Post summary

    The note reports that NocoBase versions prior to 2.0.28 contained a critical RCE flaw, but the issue has been addressed in 2.0.28. It also includes a link to the CVE record.

    0002040
    617 followersView on X
  • Boumendil Franck@BoumendilFranck
    PoC

    🚨 CVE-2026-34156 — NocoBase RCE PoC Sandbox escape via console._stdout prototype chain traversal → RCE as root, no complex setup required → Affects &lt;= 2.0.27, fixed in 2.0.28 http://github.com/franckboumendil/CVE-2026-34156 #bugbounty #infosec #CVE #RCE #nocobase #nodejs

    Post summary

    The tweet announces a PoC for CVE-2026-34156, describing a sandbox escape that leads to root RCE via console._stdout prototype traversal, includes a GitHub link to the PoC code, and notes that the issue is fixed in version 2.0.28.

    10000103
    1 followersView on X
  • TL;DR CTF with Onurcan@CtfWithOG
    Patch

    9/10 NocoBase responded same-day: acknowledged, opened fix PR, CVE assigned, patch shipped in v2.0.28. Textbook vendor response. Respect to the team. CVE-2026-34156 | GHSA-px3p-vgh9-m57c

    Post summary

    The vendor quickly acknowledged the issue, issued a patch in version 2.0.28, and the CVE is now resolved.

    1000066
    4 followersView on X
  • Security Harvester@secharvesterx
    PoC

    NocoBase CVSS 10.0: sandbox escape to root RCE through three lines of code (CVE-2026-34156) https://anonhaven.com/en/news/ocobase-sandbox-escape-rce-cve-2026-34156/ https://t.co/Gw8eVv43O1

    Post summary

    The post highlights a critical remote code execution flaw in NocoBase (CVE-2026-34156), noting its CVSS 10.0 score and that a 3‑line code PoC can trigger it, but it provides no evidence of active exploitation, patches, or detailed exploit tools.

    0001090
    906 followersView on X
  • ANONHAVEN@anonhaven_com
    Patch

    🚨 NocoBase sandbox escape to root RCE via console object prototype chain (CVE-2026-34156). A CVSS 10.0 sandbox escape in NocoBase's Workflow JavaScript node lets authenticated users reach root RCE through three lines of code. The console object leaks a host-realm Function constructor via prototype chain traversal. Patched in v2.0.28. #InfoSec #CyberSecurity #RCE #NocoBase

    Post summary

    The post reports CVE-2026-34156, a CVSS 10.0 sandbox escape leading to root RCE in NocoBase, and notes that the issue was patched in version 2.0.28; no active exploitation or PoC details are provided.

    1000062
    13 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-34156 NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.28, NocoBase's Workflow Script N… https://www.cve.org/CVERecord?id=CVE-2026-34156

    Post summary

    The snippet merely references CVE‑2026‑34156 and the NocoBase platform without providing substantive information.

    00010103
    56.9K followersView on X
  • TL;DR CTF with Onurcan@CtfWithOG
    Exploit

    10/10 Full technical writeup with methodology, all 5 enumeration phases, alternative escape vectors, and reverse shell demo: https://blog.onurcangenc.com.tr/cve-2026-34156-vm-sandbox-escape-to-rce-in-nocobase/ #AppSec #NodeJS

    Post summary

    A detailed technical writeup for CVE-2026-34156 is presented, including full methodology, enumeration phases, escape vectors, and a reverse shell demo, demonstrating a functional exploit.

    0000052
    4 followersView on X
  • CTIWatch@ctiwatchcloud
    General

    🔍 Today's Top Vulnerabilities 🔴 CVE-2026-34162 | CVSS 10.0 🔴 CVE-2026-34156 | CVSS 9.9 🔴 CVE-2026-34243 | CVSS 9.8 🔗 http://ctiwatch.cloud/vulnerabilities #CVE #Vulnerability #ThreatIntel

    Post summary

    The post lists three high‑CVSS CVEs and links to a vulnerability database, but offers no additional exploitation or remediation details.

    0000028
    5.6K followersView on X
  • ANONHAVEN@anonhaven_com
    Active Exploitation

    Source: https://anonhaven.com/en/news/ocobase-sandbox-escape-rce-cve-2026-34156/

    Post summary

    The post discloses that CVE-2026-34156, a sandbox escape causing RCE in ocobase, is actively being exploited, includes a PoC and exploit code, and cites a vendor patch.

    0000035
    12 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    `NocoBase` is affected by CVE-2026-34156, allowing authenticated users to achieve RCE via a sandbox escape in workflow scripts. #NocoBase #RCE #infosec https://www.pulsepatch.io/posts/cve-2026-34156-nocobase-sandbox-escape-rce

    Post summary

    The post announces CVE‑2026‑34156 affects NocoBase, enabling authenticated users to execute remote code via a sandbox escape in workflow scripts.

    0000034
    6 followersView on X
  • 0day Signal@0dayPublishing
    PoC

    🚨 CVE-2026-34156: NocoBase Affected by Sandbox Esc... Node.js vm sandboxes are tissue paper - console._stdout prototype traversal gives you root RCE in NocoBase's workflow e... https://zerodaysignal.com/vulnerability/CVE-2026-34156 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE-2026-34156, noting that a root RCE exists in NocoBase via a console._stdout prototype traversal in Node.js vm sandboxes, and links to a detailed report for a proof‑of‑concept.

    0000068
    194 followersView on X
  • Vulert@vulert_official
    Disclosure

    🚨 Critical NocoBase Workflow Plugin flaw CVE-2026-34156 is a remote code execution (RCE) vulnerability that could put affected applications at serious risk. 🔗 https://vulert.com/vuln-db/CVE-2026-34156 #CyberSecurity #NocoBase #RCE #AppSec #DevSecOps #OpenSourceSecurity https://t.co/x5eUQQgLI8

    Post summary

    A tweet announces CVE-2026‑34156, a remote code execution flaw in NocoBase Workflow Plugin, but provides no PoC, exploit code, or mitigation information.

    0000053
    122 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnocobasenocobase---

Explore more