CVE-2026-25520

CRITICAL

Nyariv Sandboxjs < 0.8.29 - Injection

Title source: rule
STIX 2.1

Description

SandboxJS is a JavaScript sandboxing library. Prior to 0.8.29, The return values of functions aren't wrapped. Object.values/Object.entries can be used to get an Array containing the host's Function constructor, by using Array.prototype.at you can obtain the hosts Function constructor, which can be used to execute arbitrary code outside of the sandbox. This vulnerability is fixed in 0.8.29.

Scores

CVSS v3 10.0
EPSS 0.0005
EPSS Percentile 16.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-74
Status published
Products (2)
nyariv/sandboxjs < 0.8.29
nyariv/sandboxjs 0 - 0.8.29npm
Published Feb 06, 2026
Tracked Since Feb 18, 2026