CVE-2026-23830Disclosure(nyariv / sandboxjs)

LOWCVSS 10.0 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch nyariv sandboxjs systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

SandboxJS is a JavaScript sandboxing library. Versions prior to 0.8.26 have a sandbox escape vulnerability due to `AsyncFunction` not being isolated in `SandboxFunction`. The library attempts to sandbox code execution by replacing the global `Function` constructor with a safe, sandboxed version (`SandboxFunction`). This is handled in `utils.ts` by mapping `Function` to `sandboxFunction` within a map used for lookups. However, before version 0.8.26, the library did not include mappings for `AsyncFunction`, `GeneratorFunction`, and `AsyncGeneratorFunction`. These constructors are not global properties but can be accessed via the `.constructor` property of an instance (e.g., `(async () => {}).constructor`). In `executor.ts`, property access is handled. When code running inside the sandbox accesses `.constructor` on an async function (which the sandbox allows creating), the `executor` retrieves the property value. Since `AsyncFunction` was not in the safe-replacement map, the `executor` returns the actual native host `AsyncFunction` constructor. Constructors for functions in JavaScript (like `Function`, `AsyncFunction`) create functions that execute in the global scope. By obtaining the host `AsyncFunction` constructor, an attacker can create a new async function that executes entirely outside the sandbox context, bypassing all restrictions and gaining full access to the host environment (Remote Code Execution). Version 0.8.26 patches this vulnerability.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94CWE-693CWE-913

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sandboxjs

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 11 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 10 signals
  • Disclosure: 8 classified signals
  • Peaked 4d ago at 3 mentions (2026-01-27); latest day: 1
  • 11 total mentions across 5 days

Affected systems

Vendors
Products
sandboxjs

Deep dive

Activity timeline11 mentions / 5d
01223Mentions · 2026-01-27: 3Mentions · 2026-01-28: 3Mentions · 2026-01-29: 3Mentions · 2026-02-02: 1Mentions · 2026-03-07: 1PoC Mentioned / Linked · 2026-01-29: 1Patch / Workaround · 2026-01-28: 2Technical Details · 2026-01-27: 3Technical Details · 2026-01-28: 2Technical Details · 2026-01-29: 3Technical Details · 2026-02-02: 1Technical Details · 2026-03-07: 101-2701-2801-2902-0203-07
Signal classification3 categories
Disclosure
872.7%
Patch
218.2%
PoC
19.1%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-01-273
Disclosure3
2026-01-283
Disclosure1Patch2
2026-01-293
Disclosure2PoC1
2026-02-021
Disclosure1
2026-03-071
Disclosure1
Full discourse11 posts
  • kokumօtօ@__kokumoto
    PoC

    SandboxJSにCVSSスコア10の脆弱性。同ライブラリはFunction等のグローバルオブジェクトをサンドボックス化されたもので置換することで隔離を実現するが、Async系の存在が考慮から落ちていた。(async ()=>{})だけで本物のAsyncFunctionコンストラクタを呼び出せる。 https://securityonline.info/cve-2026-23830-critical-sandboxjs-flaw-cvss-10-allows-total-sandbox-escape/

    Post summary

    CVE‑2026‑23830 exposes a CVSS 10 sandbox‑escape flaw in SandboxJS via the AsyncFunction constructor; a proof‑of‑concept is referenced in the linked security article.

    00050780
    7.2K followersView on X
  • 𝕏 Bug Bounty Writeups 𝕏@bountywriteups
    Disclosure

    Escaping the Matrix: A Deep Dive into SandboxJS RCE (CVE-2026–23830) https://medium.com/@meysam_bal-afkan/escaping-the-matrix-a-deep-dive-into-sandboxjs-rce-cve-2026-23830-1fbbca3f46fc?source=rss------bug_bounty-5 #bugbounty #bugbountytips #bugbountytip

    Post summary

    The Medium article announces a remote code execution vulnerability (CVE‑2026‑23830) in SandboxJS, but no further details such as PoC, exploit code, or patch information are present in the snippet.

    00002517
    40.2K followersView on X
  • Komodo Cyber Security@Komodosec
    Disclosure

    #VulnerabilityReport #AsyncFunction CVE-2026-23830: Critical SandboxJS Flaw (CVSS 10) Allows Total Sandbox Escape https://securityonline.info/cve-2026-23830-critical-sandboxjs-flaw-cvss-10-allows-total-sandbox-escape/?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    The tweet announces a newly disclosed critical SandboxJS vulnerability (CVE‑2026‑23830) with a CVSS score of 10 that permits complete sandbox escape, but no PoC, exploit, or mitigation is provided.

    0000037
    1.5K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-23830 (CVSS:10.0, CRITICAL) is Undergoing Analysis. SandboxJS is a JavaScript sandboxing library. Versions prior to 0.8.26 have a sandbox escape vulnerability due to `Async..https://nvd.nist.gov/vuln/detail/CVE-2026-23830 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    CVE-2026-23830 is a critical sandbox escape vulnerability in SandboxJS versions before 0.8.26, currently under analysis. No PoC, exploit, patch, or active exploitation details are provided.

    0000045
    171 followersView on X
  • Zero Day Wire@zerodaywire
    Disclosure

    🚨Critical SandboxJS Vulnerability Allows Complete Sandbox Escape and Remote Code Execution (CVE-2026-23830) 🔗 https://zerodaywire.com/article.html?slug=critical-sandboxjs-vulnerability-allows-complete-sandbox-escape-and-remote-code-execution-cve-2026-23830 #cybersecurity #infosec #threatintel https://t.co/Y8d6j2zf2c

    Post summary

    An article advertises a critical SandboxJS vulnerability (CVE‑2026‑23830) that enables sandbox escape and RCE, but it provides no PoC, exploit code, active exploitation details, or mitigation information.

    0000077
    141 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A sandbox escape vulnerability (CVE-2026-23830) affects Nyariv SandboxJS via an unprotected AsyncFunction constructor. This allows untrusted code to bypass security boundaries. #JavaScript #SandboxEscape #Infosec https://www.pulsepatch.io/posts/cve-2026-23830-sandboxjs-sandbox-escape

    Post summary

    The post discloses CVE-2026-23830 as a sandbox escape flaw in Nyariv SandboxJS triggered by an unprotected AsyncFunction constructor that allows bypassing security boundaries.

    0000047
    1 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    SandboxJS is affected by a sandbox escape via unprotected AsyncFunction Constructor (CVE-2026-23830). Systems executing untrusted JavaScript code in #SandboxJS are at risk. Update recommended. #JavaScript #Security https://www.pulsepatch.io/posts/cve-2026-23830-sandboxjs-sandbox-escape

    Post summary

    The post announces CVE-2026-23830, a sandbox escape in SandboxJS caused by an unprotected AsyncFunction Constructor, warns that systems running untrusted JavaScript are at risk, and recommends applying an update.

    0000042
    1 followersView on X
  • NCIIPC India@NCIIPC
    Patch

    Sandbox Escape Vulnerability has been discovered in #SandboxJS. Users are advised to follow OEM Security Advisory to remain safe! #CVE-2026-23830 https://nvd.nist.gov/vuln/detail/CVE-2026-23830

    Post summary

    A sandbox escape vulnerability in SandboxJS (CVE-2026-23830) has been disclosed, and users are urged to follow the OEM security advisory for remediation.

    00000146
    8.4K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-23830 SandboxJS is a JavaScript sandboxing library. Versions prior to 0.8.26 have a sandbox escape vulnerability due to `AsyncFunction` not being isolated in `SandboxFuncti… https://www.cve.org/CVERecord?id=CVE-2026-23830

    Post summary

    The passage announces a sandbox escape vulnerability in older SandboxJS versions caused by unisolated AsyncFunction usage.

    00000276
    56.5K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-23830: SandboxJS has Sandbox Escape via... Elegant RCE via overlooked AsyncFunction constructor exposes the fatal flaw in SandboxJS's isolation model - trivial es... https://zerodaysignal.com/vulnerability/CVE-2026-23830 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    A new RCE vulnerability (CVE‑2026‑23830) in SandboxJS has been disclosed, exposing a flaw in the isolation model via an overlooked AsyncFunction constructor.

    00000100
    132 followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-23830: Async Abyss: Escaping SandboxJS via Forgotten Constructors A critical oversight in SandboxJS allowed attackers to bypass the execution environment completely by leveraging the AsyncFunction constructor. While the standard Function cons... https://cvereports.com/reports/CVE-2026-23830

    Post summary

    CVE-2026-23830 reveals a critical oversight in SandboxJS that allows attackers to escape the execution sandbox by leveraging the AsyncFunction constructor, potentially enabling unrestricted code execution.

    0000053
    29 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnyarivsandboxjs-node.js-

Explore more