CVE-2026-25586Disclosure(nyariv / sandboxjs)

LOWCVSS 10.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch nyariv sandboxjs systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

SandboxJS is a JavaScript sandboxing library. Prior to 0.8.29, a sandbox escape is possible by shadowing hasOwnProperty on a sandbox object, which disables prototype whitelist enforcement in the property-access path. This permits direct access to __proto__ and other blocked prototype properties, enabling host Object.prototype pollution and persistent cross-sandbox impact. This vulnerability is fixed in 0.8.29.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sandboxjs

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 7 signals
  • Disclosure: 4 classified signals
  • Peaked 2d ago at 5 mentions (2026-02-06); latest day: 1
  • 7 total mentions across 3 days

Affected systems

Vendors
Products
sandboxjs

Deep dive

Activity timeline7 mentions / 3d
01345Mentions · 2026-02-06: 5Mentions · 2026-02-07: 1Mentions · 2026-02-09: 1Patch / Workaround · 2026-02-06: 2Patch / Workaround · 2026-02-07: 1Patch / Workaround · 2026-02-09: 1Technical Details · 2026-02-06: 5Technical Details · 2026-02-07: 1Technical Details · 2026-02-09: 102-0602-0702-09
Signal classification2 categories
Disclosure
457.1%
Patch
342.9%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-065
Disclosure3Patch2
2026-02-071
Patch1
2026-02-091
Disclosure1
Full discourse7 posts
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-25586: SandboxJS has a Sandbox Escape v... Brilliant prototype chain attack in SandboxJS - shadow hasOwnProperty to bypass whitelist checks, gain __proto__ access... https://zerodaysignal.com/vulnerability/CVE-2026-25586 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE-2026-25586, a Sandbox Escape in SandboxJS, describing a prototype chain attack that bypasses whitelist checks via shadow hasOwnProperty and gains __proto__ access, but does not provide PoC, exploit code, or patch details.

    00032335
    132 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25586 SandboxJS is a JavaScript sandboxing library. Prior to 0.8.29, a sandbox escape is possible by shadowing hasOwnProperty on a sandbox object, which disables prototype … https://www.cve.org/CVERecord?id=CVE-2026-25586

    Post summary

    The passage reports a sandbox escape vulnerability in SandboxJS (CVE‑2026‑25586) where shadowing hasOwnProperty allows escape in versions before 0.8.29; it lacks PoC, exploit code, patch, or evidence of active exploitation.

    00021207
    56.5K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-25586: CRITICAL] Security alert! SandboxJS JavaScript sandboxing library had a critical vulnerability allowing sandbox escapes. Update to version 0.8.29 to fix the issue and prevent cyberattacks.#cve,CVE-2026-25586,#cybersecurity https://cvefind.com/CVE-2026-25586

    Post summary

    A security alert warns of a critical sandbox escape in SandboxJS and recommends upgrading to version 0.8.29 to mitigate the risk.

    1000090
    583 followersView on X
  • PurpleOps@PurpleOps_io
    Disclosure

    🔍 𝐂𝐨𝐝𝐞 𝐑𝐞𝐝: 𝟒 𝐂𝐫𝐢𝐭𝐢𝐜𝐚𝐥 𝐒𝐚𝐧𝐝𝐛𝐨𝐱𝐉𝐒 𝐅𝐥𝐚𝐰𝐬 (𝐂𝐕𝐒𝐒 𝟏𝟎.𝟎) 𝐀𝐥𝐥𝐨𝐰 𝐇𝐨𝐬𝐭 𝐓𝐚𝐤𝐞𝐨𝐯𝐞𝐫 • Four critical vulnerabilities (CVE-2026-25520, CVE-2026-25586, CVE-2026-25587, CVE-2026-25641) were found in SandboxJS. • All flaws carry a maximum CVSS score of 10.0, enabling host takeover. • SandboxJS versions 0.8.28 and earlier are affected; version 0.8.29 contains the patch. Four critical SandboxJS vulnerabilities, rated CVSS 10.0, allow attackers to bypass security and execute code on the host system.

    Post summary

    Four critical SandboxJS vulnerabilities (CVE‑2026‑25520, 25586, 25587, 25641) were disclosed, all with CVSS 10.0 enabling host takeover; version 0.8.29 includes the patch.

    0000063
    64 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 CRITICAL: SandboxJS < 0.8.29 allows sandbox escape via prototype pollution! Risk: remote code execution & cross-sandbox impact. Patch now to protect your JS environments. https://radar.offseq.com/threat/cve-2026-25586-cwe-74-improper-neutralization-of-s-3231fe20 #OffSeq #CVE... https://t.co/Y9UgIJsGhm

    Post summary

    CVE‑2026‑25586 in SandboxJS enables remote code execution through prototype pollution; patching is urgently recommended.

    0000061
    268 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-25586 - Critical SandboxJS is a JavaScript sandboxing library. Prior to 0.8.29, a sandbox escape is possible by shadowing hasOwnProperty on a sandbox object, which disables prototype whitelist enforcement... https://www.thehackerwire.com/vulnerability/CVE-2026-25586/ https://t.co/Qwe0pUMoR7

    Post summary

    The tweet announces CVE‑2026‑25586, a critical sandbox escape in SandboxJS v0.8.28 and earlier, where shadowing hasOwnProperty disables prototype whitelist enforcement. No PoC, exploit code, or patch information is provided.

    0000050
    113 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    SandboxJS is affected by a sandbox escape via prototype pollution (CVE-2026-25586). Update to version 0.8.29. #JavaScript #SandboxEscape #Infosec https://www.pulsepatch.io/posts/cve-2026-25586-sandboxjs-sandbox-escape-vulnerability

    Post summary

    The tweet highlights a prototype‑pollution‑based sandbox escape in SandboxJS (CVE‑2026‑25586) and urges users to update to version 0.8.29 to mitigate the issue.

    0000056
    1 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnyarivsandboxjs-node.js-

Explore more