This is a heavily interactive web application, and JavaScript is required. Simple HTML interfaces are possible, but that is not what this is.
Post
BaseFortify.eu
basefortify.bsky.social
did:plc:giplx3mfo7nnb44f3yzhclu3
🧩 How the escape works
By triggering a tool error, sandboxed code receives a host Error object. Its prototype chain can be traversed to reach the host Function constructor, enabling arbitrary code execution in the host context. 🪜⚠️
#AppSec #SandboxEscape #RCE #AIsecurity
2026-01-14T10:43:00.316Z