CVE-2026-26954

SandboxJS is a JavaScript sandboxing library. Prior to 0.8.34, it is possible to obtain arrays containing Function, which allows escaping the sandbox. Given an array containing Function, and Object.fromEntries, it is possible to construct {[p]: Function} where p is any constructible property. This vulnerability is fixed in 0.8.34.
Configurations

Configuration 1 (hide)

cpe:2.3:a:nyariv:sandboxjs:*:*:*:*:*:node.js:*:*

History

17 Jun 2026, 10:26

Type Values Removed Values Added
References () https://github.com/nyariv/SandboxJS/security/advisories/GHSA-6r9f-759j-hjgv - Vendor Advisory, Exploit () https://github.com/nyariv/SandboxJS/security/advisories/GHSA-6r9f-759j-hjgv - Exploit, Vendor Advisory
Summary
  • (es) SandboxJS es una biblioteca de sandboxing de JavaScript. Antes de 0.8.34, es posible obtener arrays que contienen Function, lo que permite escapar del sandbox. Dado un array que contiene Function, y Object.fromEntries, es posible construir {[p]: Function} donde p es cualquier propiedad construible. Esta vulnerabilidad se corrige en la versión 0.8.34.

17 Mar 2026, 20:13

Type Values Removed Values Added
CPE cpe:2.3:a:nyariv:sandboxjs:*:*:*:*:*:node.js:*:*
First Time Nyariv sandboxjs
Nyariv
References () https://github.com/nyariv/SandboxJS/security/advisories/GHSA-6r9f-759j-hjgv - () https://github.com/nyariv/SandboxJS/security/advisories/GHSA-6r9f-759j-hjgv - Vendor Advisory, Exploit

16 Mar 2026, 18:16

Type Values Removed Values Added
References () https://github.com/nyariv/SandboxJS/security/advisories/GHSA-6r9f-759j-hjgv - () https://github.com/nyariv/SandboxJS/security/advisories/GHSA-6r9f-759j-hjgv -

13 Mar 2026, 19:54

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-13 19:54

Updated : 2026-06-17 10:26


NVD link : CVE-2026-26954

Mitre link : CVE-2026-26954

CVE.ORG link : CVE-2026-26954


JSON object : View

Products Affected

nyariv

  • sandboxjs
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')