CVE-2021-42952
Critical · CVSS 9.9Zepl Notebooks — Sandbox Escape leading to Remote Code Execution and Cloud Metadata Service Access
- CVSS
- 9.9
- nvd
- EPSS
- —
- KEV
- No
- Class
- other
- NVD-CWE-noinfo
Description
Zepl Notebooks before 2021-10-25 are affected by a sandbox escape vulnerability. Upon launching Remote Code Execution from the Notebook, users can then use that to subsequently escape the running context sandbox and proceed to access internal Zepl assets including cloud metadata services.
Search profile — drives PoC discovery
Symbols sandbox escapeRCEcloud metadataIMDSnotebook execution contextremote code execution
Keywords CVE-2021-42952Zepl Notebooks sandbox escapeZepl RCEZepl cloud metadataZepl notebook sandbox bypassZepl IMDS accessZepl internal assets exposure
Versions: before 2021-10-25
References
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T06:30:39.000Z