📦 Sandboxjs

by Nyariv

🔍 What is Sandboxjs?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2026-25881

CRITICAL CVSS 9.0 Feb 9, 2026

This CVE describes a sandbox escape vulnerability in SandboxJS library versions before 0.8.31. It allows sandboxed JavaScript code to bypass isolation protections and modify host-side built-in prototy...

CVE-2026-25641

CRITICAL CVSS 10.0 Feb 6, 2026

CVE-2026-25641 is a sandbox escape vulnerability in SandboxJS library versions before 0.8.29. Attackers can bypass JavaScript sandbox restrictions by passing malicious objects that coerce to different...

CVE-2026-25520

CRITICAL CVSS 10.0 Feb 6, 2026

SandboxJS versions before 0.8.29 have a critical sandbox escape vulnerability that allows attackers to obtain the host's Function constructor and execute arbitrary code outside the sandbox. This affec...

CVE-2026-25586

CRITICAL CVSS 10.0 Feb 6, 2026

This CVE describes a sandbox escape vulnerability in SandboxJS library versions before 0.8.29. Attackers can bypass JavaScript sandboxing by shadowing the hasOwnProperty method, allowing access to blo...

CVE-2026-25587

CRITICAL CVSS 10.0 Feb 6, 2026

CVE-2026-25587 is a critical sandbox escape vulnerability in SandboxJS library versions before 0.8.29. Attackers can overwrite Map.prototype.has to break out of the JavaScript sandbox and execute arbi...

CVE-2026-25142

CRITICAL CVSS 10.0 Feb 2, 2026

CVE-2026-25142 is a critical sandbox escape vulnerability in SandboxJS library versions before 0.8.27. Attackers can use the __lookupGetter__ method to access prototypes and execute arbitrary code out...

CVE-2026-23830

CRITICAL CVSS 10.0 Jan 28, 2026

SandboxJS versions before 0.8.26 have a critical sandbox escape vulnerability that allows attackers to execute arbitrary code outside the sandbox context. This occurs because AsyncFunction, GeneratorF...