Executive brief
KanaDojo, a language learning application, contains a security flaw in its automated GitHub workflow. An attacker can submit a malicious pull request that escapes the software's security sandbox to execute unauthorized commands. This could allow an attacker to take control of the project's build environment and steal sensitive automation tokens.
Technical details
A sandbox escape vulnerability exists in KanaDojo's 'issue-auto-respond.yml' workflow due to the insecure use of the Node.js 'vm.runInNewContext()' function. The workflow explicitly passes the global 'require' function into the sandbox context, allowing an attacker to bypass intended isolation. By submitting a pull request that modifies 'messages.cjs', an attacker can import arbitrary Node.js modules to achieve remote code execution (RCE). This exploit provides the attacker with the full privileges of the GitHub Actions runner, including access to the 'AUTOMATION_PR_TOKEN'. The issue is fixed in version 0.1.18 by removing 'require' from the VM sandbox.
Affected products
- lingdojo KanaDojo before 0.1.18
Timeline
- 2026-05-27: patched: Version 0.1.18 released
- 2026-06-11: disclosed: CVE-2026-48546 published