Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

sandboxjs — Vulnerabilities & Security Advisories 14

All 14 CVE vulnerabilities found in sandboxjs, with AI-generated Chinese analysis, references, and POCs.

This page aggregates common weakness information for the sandboxjs software product, focusing on vulnerability classifications and associated security risks. It collects data regarding various vulnerability types, including cross-site scripting, insecure default configurations, and resource management errors, covering records from initial discovery up to the most recent updates. Visitors can track vendor advisories to stay informed about patches and mitigations, understand the broader context of specific weakness classes within this JavaScript sandbox environment, and look up the complete vulnerability history to assess long-term security trends. The page serves as a centralized resource for security researchers, developers, and system administrators who need to evaluate the risk profile of sandboxjs instances. By consolidating disparate sources of information, it allows users to correlate known exploits with specific code versions or deployment scenarios. This aggregation helps in prioritizing remediation efforts by highlighting high-severity issues and recurring patterns. The content is organized to facilitate quick reference and deep analysis, ensuring that stakeholders have access to accurate and timely data without navigating multiple external databases. Whether you are conducting a security audit or implementing new security controls, this page provides the necessary historical and current context to make informed decisions. The information presented here is derived from verified sources and is updated regularly to reflect the latest findings in the security community.

Vendor: nyariv

CVE ID Title CVSS Severity Published
CVE-2026-43898 SandboxJS: Sandbox escape via Function.caller leakage of internal call op CWE-94 10.0 Critical 2026-05-28
CVE-2026-34217 SandboxJS has a Sandbox Escape via Prop Object Leak in New Handler CWE-668 9.3AI Critical AI 2026-04-06
CVE-2026-34211 SandboxJS: Stack overflow DoS via deeply nested expressions in recursive descent parser CWE-674 7.5AI High AI 2026-04-06
CVE-2026-34208 SandboxJS: Sandbox integrity escape CWE-693 10.0 Critical 2026-04-06
CVE-2026-32723 SandboxJS timers have an execution-quota bypass (cross-sandbox currentTicks race) CWE-362 9.8 - 2026-03-18
CVE-2026-26954 SandboxJS has a Sandbox Escape CWE-94 10.0 Critical 2026-03-13
CVE-2026-25881 @nyariv/sandboxjs has host prototype pollution from sandbox via array intermediary (sandbox escape) CWE-1321 9.1 Critical 2026-02-09
CVE-2026-25586 SandboxJS has a Sandbox Escape via Prototype Whitelist Bypass and Host Prototype Pollution CWE-74 10.0 Critical 2026-02-06
CVE-2026-25520 SandboxJS has a Sandbox Escape CWE-74 10.0 Critical 2026-02-06
CVE-2026-25587 SandboxJS has a Sandbox Escape CWE-94 10.0 Critical 2026-02-06
CVE-2026-25641 SandboxJS has a sandbox escape via TOCTOU bug on keys in property accesses CWE-367 10.0 Critical 2026-02-06
CVE-2026-25142 SandboxJS Prototype Pollution -> Sandbox Escape -> RCE CWE-94 10.0 Critical 2026-02-02
CVE-2026-23830 SandboxJS has Sandbox Escape via Unprotected AsyncFunction Constructor CWE-94 10.0 Critical 2026-01-27
CVE-2025-34146 nyariv sandboxjs 0.8.23 Prototype Pollution Sandbox Escape DoS CWE-1321 9.8AI Critical AI 2025-07-31

All 14 known CVE vulnerabilities affecting sandboxjs with full Chinese analysis, references, and POCs where available.