VulnSea

CWE-653

CVEs classified under CWE-653, newest first.

20 CVEsRSS

CVE-2026-82964High· 8.8PoC
5d ago

Improper preservation of permissions in the Avast sandbox minifilter driver (aswSnx.sys) on Windows allows a local, low-privileged attacker executing inside the sandbox to escape file isolation and escalate to SYSTEM. When the sandbox…

Improper preservation of permissions in the Avast sandbox minifilter driver (aswSnx.sys) on Windows allows a local, low-privileged attacker executing inside the sandbox to escape file isolation and escalate to SYSTEM. When the sandbox…

MidnightGen Digital · Avast Free Antivirus, Avast One, Avast Premium Security, Avast Ultimate, Avast Business SecurityEPSS 0.14%via NVD
CVE-2026-92006High· 8.8
6d ago

Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component

Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16…

TwilightMozilla · FirefoxEPSS 0.35%via NVD
CVE-2026-92034Critical· 9.1
6d ago

Site isolation issue in the Graphics component

Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.

MidnightMozilla · FirefoxEPSS 0.15%via NVD
CVE-2026-92045Critical· 9.6⚖ disputed
6d ago

Sandbox escape due to incorrect boundary conditions in the WebRTC component

Sandbox escape due to incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

MidnightMozilla · FirefoxEPSS 0.15%via NVD
CVE-2026-92066Critical· 9.8⚖ disputed
6d ago

Sandbox escape in the Profile Backup component

Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.

MidnightMozilla · FirefoxEPSS 0.14%via NVD
CVE-2026-92068Low· 3.4
6d ago

Site isolation issue in the Reader Mode component

Site isolation issue in the Reader Mode component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

SunlitMozilla · FirefoxEPSS 0.14%via NVD
CVE-2026-57135High· 7.6PoC
6d ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, SandboxExecutor network-isolated mode in src/praisonai-ts/src/cli/features/sandbox-executor.ts uses buildEnv() only to inject invalid http_proxy and https_proxy environment…

MidnightMervinPraison · PraisonAIEPSS 0.31%via NVD
CVE-2026-74934High· 7.5
1mo ago

Site isolation issue in the Graphics: CanvasWebGL component

Site isolation issue in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 10)EPSS 0.16%via NVD
CVE-2026-71325Medium· 4.4⚖ disputed
1mo ago

Traefik is an open-source edge router that makes publishing services a fun and easy experience

Traefik is an open-source edge router that makes publishing services a fun and easy experience. Prior to 2.11.54, 3.6.25, and 3.7.10, cross-namespace @kubernetescrd references are not rejected for TraefikService backend references resolv…

Sunlittraefik · traefikEPSS 0.14%via NVD
CVE-2026-62246High· 8.5
1mo ago

Kamaji is the Hosted Control Plane Manager for Kubernetes

Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, Kamaji derives a TenantControlPlane datastore schema, database user, and etcd key prefix from a lossy namespace-and-name normalization in GetDefaultDatastor…

TwilightEPSS 0.27%via NVD
GHSA-gqmf-56h7-rrpfHigh· 7.6
3mo ago

npm PraisonAI SandboxExecutor network-isolated mode does not block non-proxy-aware network clients

npm PraisonAI SandboxExecutor network-isolated mode does not block non-proxy-aware network clients

Twilightpraisonai · praisonaivia GHSA
CVE-2026-12297Critical· 9.6
3mo ago

Sandbox escape due to incorrect boundary conditions in the Networking component

Sandbox escape due to incorrect boundary conditions in the Networking component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.

Midnightmozilla · firefoxEPSS 0.39%via NVD
CVE-2026-12295Critical· 9.6PoC
3mo ago

Sandbox escape in the DOM: Navigation component

Sandbox escape in the DOM: Navigation component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.

Abyssalmozilla · firefoxEPSS 0.39%via NVD
CVE-2026-44009Critical· 9.8
4mo ago

vm2 is an open source vm/sandbox for Node.js

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, This vulnerability is fixed in 3.11.2.

Midnightvm2_project · vm2EPSS 0.81%via NVD
CVE-2026-44005Critical· 10.0
4mo ago

vm2 is an open source vm/sandbox for Node.js

vm2 is an open source vm/sandbox for Node.js. From 3.9.6 to 3.10.5, vm2's bridge exposes mutable proxies for real host-realm intrinsic prototypes and then forwards sandbox writes into the underlying host objects with otherReflectSet() an…

Midnightvm2_project · vm2EPSS 0.83%via NVD
CVE-2026-43997Critical· 10.0
4mo ago

vm2 is an open source vm/sandbox for Node.js

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, it is possible to obtain the host Object. There are various ways to use the host Object, to escape the sandbox, one example would be using HostObject.getOwnPropertySymbols to…

Midnightvm2_project · vm2EPSS 0.98%via NVD
CVE-2026-24781Critical· 9.8
4mo ago

vm2 is an open source vm/sandbox for Node.js

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability through the inspect function. This allows attackers to write code which can escape from the VM2 sandbox and execute …

Midnightvm2_project · vm2EPSS 1.2%via NVD
CVE-2026-5599None
5mo ago

A user with API access and "manage users" permission in any venueless world is able to trigger deletion of user accounts in other worlds.

A user with API access and "manage users" permission in any venueless world is able to trigger deletion of user accounts in other worlds.

SunlitEPSS 0.25%via NVD
CVE-2024-23683High· 8.2
2y ago

Artemis Java Test Sandbox versions less than 1.7.6 are vulnerable to a sandbox escape when an attacker crafts a special subclass of InvocationTargetException

Artemis Java Test Sandbox versions less than 1.7.6 are vulnerable to a sandbox escape when an attacker crafts a special subclass of InvocationTargetException. An attacker can abuse this issue to execute arbitrary Java when a victim execu…

Twilightls1intum · artemis_java_test_sandboxEPSS 0.36%via NVD
CVE-2024-23682High· 8.2
2y ago

Artemis Java Test Sandbox versions before 1.8.0 are vulnerable to a sandbox escape when an attacker includes class files in a package that Ares trusts

Artemis Java Test Sandbox versions before 1.8.0 are vulnerable to a sandbox escape when an attacker includes class files in a package that Ares trusts. An attacker can abuse this issue to execute arbitrary Java when a victim executes the…

Twilightls1intum · artemis_java_test_sandboxEPSS 0.35%via NVD
CWE-653 vulnerabilities (CVEs) · VulnSea