Sandboxie 5.26 allows a Sandbox Escape via an import os statement, followed by os.system(cmd) or os.system(powershell), within a .py file. NOTE: the vendor disputes this issue because the observed behavior is consistent with the products intended functionality
Name | Vendor | Start Version | End Version |
---|---|---|---|
Sandboxie | Sandboxie | 5.26 (including) | 5.26 (including) |