Yes, it says right in the CVE
> allowed a remote attacker to execute arbitrary code *inside the sandbox*