Detects NocoBase instances before version 2.0.28 where the Workflow JavaScript plugin's VM sandbox exposes the host console._stdout object. An authenticated user can traverse the prototype chain (console._stdout.constructor.constructor) to escape the sandbox and execute arbitrary OS commands as root. The verifier confirms the vulnerable version and active workflow plugin endpoint without executing the exploit.
Is your app exploitable through CVE-2026-34156?
Scan your domain free