CVE-2026-25586: Nyariv Sandboxjs

Critical severity, CVSS 10.0. EPSS: 0.7% chance of exploitation in the next 30 days.

SandboxJS is a JavaScript sandboxing library. Prior to 0.8.29, a sandbox escape is possible by shadowing hasOwnProperty on a sandbox object, which disables prototype whitelist enforcement in the property-access path. This permits direct access to __proto__ and other blocked prototype properties, enabling host Object.prototype pollution and persistent cross-sandbox impact. This vulnerability is fixed in 0.8.29.

Affected products

  • Nyariv Sandboxjs: before 0.8.29 (fixed in 0.8.29)

Published 2026-02-06. Last modified 2026-06-17.