A vulnerability was identified in ByteDance verl up to 0.7.0. Affected is the function math_equal of the file prime_math/grader.py. The manipulation leads to sandbox issue. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-6878 is a sandbox escape vulnerability in ByteDance verl versions up to 0.7.0 affecting the math_equal function in prime_math/grader.py. The vulnerability allows remote attackers to bypass sandbox restrictions, though exploitation is complex and difficult.
ثغرة في ByteDance verl تؤثر على الإصدارات حتى 0.7.0 في دالة math_equal بملف prime_math/grader.py. تسمح الثغرة بتجاوز قيود الحماية (sandbox) من خلال هجوم بعيد، لكن الاستغلال يتطلب تعقيداً عالياً. تم نشر استغلال عام للثغرة والبائع لم يستجب للإفصاح المبكر.
A sandbox bypass vulnerability exists in ByteDance verl up to version 0.7.0 in the math_equal function. Remote exploitation is possible but requires high complexity and difficult execution techniques.
Update ByteDance verl to version 0.7.1 or later when available. Implement network segmentation to restrict remote access to systems running affected versions. Monitor for suspicious activity related to sandbox bypass attempts. Apply principle of least privilege to limit impact of potential exploitation.
قم بتحديث ByteDance verl إلى الإصدار 0.7.1 أو أحدث عند توفره. طبق تقسيم الشبكة لتقييد الوصول البعيد للأنظمة التي تعمل بالإصدارات المتأثرة. راقب الأنشطة المريبة المتعلقة بمحاولات الهروب من الحماية. طبق مبدأ الامتيازات الأقل للحد من تأثير الاستغلال المحتمل.