PurpleOps[verified]@PurpleOps_ioDisclosure
Four critical SandboxJS vulnerabilities (CVE‑2026‑25520, 25586, 25587, 25641) were disclosed, all with CVSS 10.0 enabling host takeover; version 0.8.29 includes the patch.
OffSeq | Adversary Tactics for Cyber Resilience[verified]@offseqPatch
CVE‑2026‑25586 in SandboxJS enables remote code execution through prototype pollution; patching is urgently recommended.
0day Signal@0dayPublishingDisclosure
The tweet announces CVE-2026-25586, a Sandbox Escape in SandboxJS, describing a prototype chain attack that bypasses whitelist checks via shadow hasOwnProperty and gains __proto__ access, but does not provide PoC, exploit code, or patch details.
CVE@CVEnewDisclosure
The passage reports a sandbox escape vulnerability in SandboxJS (CVE‑2026‑25586) where shadowing hasOwnProperty allows escape in versions before 0.8.29; it lacks PoC, exploit code, patch, or evidence of active exploitation.
CVEFind.com@CveFindComPatch
A security alert warns of a critical sandbox escape in SandboxJS and recommends upgrading to version 0.8.29 to mitigate the risk.
The Hacker Wire@TheHackerWireDisclosure
The tweet announces CVE‑2026‑25586, a critical sandbox escape in SandboxJS v0.8.28 and earlier, where shadowing hasOwnProperty disables prototype whitelist enforcement. No PoC, exploit code, or patch information is provided.
PulsePatch.io@pulsepatchioPatch
The tweet highlights a prototype‑pollution‑based sandbox escape in SandboxJS (CVE‑2026‑25586) and urges users to update to version 0.8.29 to mitigate the issue.