CVE-2026-25142Patch(nyariv / sandboxjs)

LOWCVSS 10.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch nyariv sandboxjs systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

SandboxJS is a JavaScript sandboxing library. Prior to 0.8.27, SanboxJS does not properly restrict __lookupGetter__ which can be used to obtain prototypes, which can be used for escaping the sandbox / remote code execution. This vulnerability is fixed in 0.8.27.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94CWE-1321

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sandboxjs

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-02-02); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
sandboxjs

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-02: 2Mentions · 2026-02-03: 1Patch / Workaround · 2026-02-02: 1Patch / Workaround · 2026-02-03: 1Technical Details · 2026-02-02: 2Technical Details · 2026-02-03: 102-0202-03
Signal classification2 categories
Patch
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-022
Disclosure1Patch1
2026-02-031
Patch1
Full discourse3 posts
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-25142: CRITICAL] JavaScript sandboxing library SandboxJS fixed a vulnerability in version 0.8.27 that could lead to remote code execution by not properly restricting __lookupGetter__.#cve,CVE-2026-25142,#cybersecurity https://cvefind.com/CVE-2026-25142

    Post summary

    The tweet announces that CVE-2026-25142, a critical remote code execution flaw in SandboxJS, has been patched in version 0.8.27; no PoC, exploit code, or active exploitation is reported.

    0000072
    583 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25142 SandboxJS is a JavaScript sandboxing library. Prior to 0.8.27, SanboxJS does not properly restrict __lookupGetter__ which can be used to obtain prototypes, which can … https://www.cve.org/CVERecord?id=CVE-2026-25142

    Post summary

    The text reports CVE-2026-25142, indicating SandboxJS prior to 0.8.27 fails to restrict __lookupGetter__, allowing prototype access.

    00000134
    56.5K followersView on X
  • 0day Signal@0dayPublishing
    Patch

    🚨 CVE-2026-25142: SandboxJS Prototype Pollution ->... Trivial sandbox escape in SandboxJS via __lookupGetter__ prototype pollution - upgrade now or watch attackers pivot fro... https://zerodaysignal.com/vulnerability/CVE-2026-25142 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    CVE-2026-25142 is a prototype pollution flaw in SandboxJS that allows sandbox escape; the tweet urges users to upgrade promptly.

    0000037
    132 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnyarivsandboxjs-node.js-

Explore more