CVE-2026-25587: Nyariv Sandboxjs
Critical severity, CVSS 10.0. EPSS: 0.7% chance of exploitation in the next 30 days.
SandboxJS is a JavaScript sandboxing library. Prior to 0.8.29, as Map is in SAFE_PROTOYPES, it's prototype can be obtained via Map.prototype. By overwriting Map.prototype.has the sandbox can be escaped. This vulnerability is fixed in 0.8.29.
Affected products
- Nyariv Sandboxjs: before 0.8.29 (fixed in 0.8.29)
Published 2026-02-06. Last modified 2026-06-17.