CVE-2026-25587
EUVD-2026-559006.02.2026, 20:16
SandboxJS is a JavaScript sandboxing library. Prior to 0.8.29, as Map is in SAFE_PROTOYPES, it's prototype can be obtained via Map.prototype. By overwriting Map.prototype.has the sandbox can be escaped. This vulnerability is fixed in 0.8.29.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| nyariv | sandboxjs | 𝑥 < 0.8.29 |
𝑥
= Vulnerable software versions