CVE-2026-25586
EUVD-2026-559206.02.2026, 20:16
SandboxJS is a JavaScript sandboxing library. Prior to 0.8.29, a sandbox escape is possible by shadowing hasOwnProperty on a sandbox object, which disables prototype whitelist enforcement in the property-access path. This permits direct access to __proto__ and other blocked prototype properties, enabling host Object.prototype pollution and persistent cross-sandbox impact. This vulnerability is fixed in 0.8.29.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| nyariv | sandboxjs | 𝑥 < 0.8.29 |
𝑥
= Vulnerable software versions