CVE-2026-25520Patch(nyariv / sandboxjs)

LOWCVSS 10.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch nyariv sandboxjs systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

SandboxJS is a JavaScript sandboxing library. Prior to 0.8.29, The return values of functions aren't wrapped. Object.values/Object.entries can be used to get an Array containing the host's Function constructor, by using Array.prototype.at you can obtain the hosts Function constructor, which can be used to execute arbitrary code outside of the sandbox. This vulnerability is fixed in 0.8.29.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sandboxjs

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 5 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 3 mentions (2026-02-06); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
sandboxjs

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-02-06: 3Mentions · 2026-02-07: 1Mentions · 2026-02-09: 1Patch / Workaround · 2026-02-06: 1Patch / Workaround · 2026-02-07: 1Patch / Workaround · 2026-02-09: 1Technical Details · 2026-02-06: 3Technical Details · 2026-02-07: 1Technical Details · 2026-02-09: 102-0602-0702-09
Signal classification2 categories
Patch
360.0%
Disclosure
240.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-063
Disclosure2Patch1
2026-02-071
Patch1
2026-02-091
Patch1
Full discourse5 posts
  • PurpleOps@PurpleOps_io
    Patch

    🔍 𝐂𝐨𝐝𝐞 𝐑𝐞𝐝: 𝟒 𝐂𝐫𝐢𝐭𝐢𝐜𝐚𝐥 𝐒𝐚𝐧𝐝𝐛𝐨𝐱𝐉𝐒 𝐅𝐥𝐚𝐰𝐬 (𝐂𝐕𝐒𝐒 𝟏𝟎.𝟎) 𝐀𝐥𝐥𝐨𝐰 𝐇𝐨𝐬𝐭 𝐓𝐚𝐤𝐞𝐨𝐯𝐞𝐫 • Four critical vulnerabilities (CVE-2026-25520, CVE-2026-25586, CVE-2026-25587, CVE-2026-25641) were found in SandboxJS. • All flaws carry a maximum CVSS score of 10.0, enabling host takeover. • SandboxJS versions 0.8.28 and earlier are affected; version 0.8.29 contains the patch. Four critical SandboxJS vulnerabilities, rated CVSS 10.0, allow attackers to bypass security and execute code on the host system.

    Post summary

    Four CVEs in SandboxJS with CVSS 10.0 enable host takeover; patch is available in version 0.8.29.

    0000063
    64 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-25520: CRITICAL] JavaScript sandboxing library SandboxJS has fixed a vulnerability in version 0.8.29 where the hosts' Function constructor could be accessed, allowing execution of arbitrary code ou...#cve,CVE-2026-25520,#cybersecurity https://cvefind.com/CVE-2026-25520

    Post summary

    SandboxJS version 0.8.29 had a critical flaw (CVE‑2026‑25520) where the host’s Function constructor was exposed, allowing arbitrary code execution; a patch for this issue is now available, with no evidence of active exploitation or a proof‑of‑concept.

    0000069
    583 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25520 SandboxJS is a JavaScript sandboxing library. Prior to 0.8.29, The return values of functions aren't wrapped. Object.values/Object.entries can be used to get an Array… https://www.cve.org/CVERecord?id=CVE-2026-25520

    Post summary

    The text reports a SandboxJS vulnerability (CVE‑2026‑25520) where function return values are not wrapped, enabling array extraction via Object.values/Object.entries. No PoC, exploit, patch, or active exploitation is mentioned.

    00000202
    56.5K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-25520 - Critical SandboxJS is a JavaScript sandboxing library. Prior to 0.8.29, The return values of functions aren't wrapped. Object.values/Object.entries can be used to get an Array containing the host'... https://www.thehackerwire.com/vulnerability/CVE-2026-25520/ https://t.co/kQdS6uaWuz

    Post summary

    The post announces CVE‑2026‑25520 in SandboxJS, noting that pre‑0.8.29 return values aren’t wrapped and can be accessed via Object.values/Object.entries. No PoC, patch, or active exploitation details are provided.

    0000040
    113 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    Nyariv SandboxJS users: A sandbox escape (CVE-2026-25520) has been addressed in version 0.8.29. This vulnerability could lead to arbitrary code execution outside the sandbox. Patching is advised. #infosec #javascript #security https://www.pulsepatch.io/posts/cve-2026-25520-nyariv-sandboxjs-sandbox-escape

    Post summary

    The post announces that CVE-2026-25520, a sandbox escape leading to potential arbitrary code execution, has been fixed in Nyariv SandboxJS v0.8.29 and urges users to patch.

    0000055
    1 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnyarivsandboxjs-node.js-

Explore more