CVE-2026-30856: Weknora Sandbox Missing Validation

The function directly executes sandbox configurations without prior validation. If this configuration is supplied by an untrusted source (e.g., LLM generation), it can lead to arbitrary code execution vulnerabilities within the sandbox.

Provally CuratedPublic repositoryHighMedium confidenceVerifiedApache-2.0Go
greprules fetch cve-2026-30856-weknora-sandbox-missing-validation --engine opengrep

Description

The function directly executes sandbox configurations without prior validation. If this configuration is supplied by an untrusted source (e.g., LLM generation), it can lead to arbitrary code execution vulnerabilities within the sandbox.