Impact
CVE-2026-34156 affects @nocobase/plugin-workflow-javascript through version 2.0.27 and is fixed in 2.0.28 [S1][S2][S3]. An authenticated user with permission to execute a Workflow Script Node could escape the intended JavaScript sandbox and run code in the NocoBase host process context [S1]. The vendor and reviewed GitHub advisory rate the issue Critical at CVSS 9.9, while the required authenticated workflow access remains an important deployment-specific precondition [S1][S2].
Root cause
The vulnerable Workflow Script Node exposed console streams created in the host JavaScript realm to sandboxed code. Those host-realm objects could be abused to cross the sandbox boundary, defeating the intended isolation [S1]. NocoBase corrected the implementation in the 2.0.28 release [S4][S5].
How FixVibe covers it
FixVibe's GitHub repo scans flag the @nocobase/plugin-workflow-javascript package when an affected version is present in npm manifests or npm, Yarn and pnpm lockfiles, with the version, affected range and patched version.
Remediation
Upgrade NocoBase and @nocobase/plugin-workflow-javascript to version 2.0.28 or newer [S1][S4]. Regenerate the active lockfile, rebuild server and container artifacts, and verify the deployed dependency tree. Restrict workflow editing and Script Node testing to trusted administrators, run the service with least-privilege credentials as a non-root user, and review workflow or audit logs if untrusted users may have had access before the upgrade.
Sources
- NocoBase security advisory [S1]
- GitHub reviewed advisory [S2]
- NVD CVE record [S3]
- NocoBase 2.0.28 release [S4]
- Upstream fix pull request [S5]
