CVE-2026-25641Disclosure(nyariv / sandboxjs)

MEDIUMCVSS 9.0 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch nyariv sandboxjs systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

SandboxJS is a JavaScript sandboxing library. Prior to 0.8.29, there is a sandbox escape vulnerability due to a mismatch between the key on which the validation is performed and the key used for accessing properties. Even though the key used in property accesses is annotated as string, this is never enforced. So, attackers can pass malicious objects that coerce to different string values when used, e.g., one for the time the key is sanitized using hasOwnProperty(key) and a different one for when the key is used for the actual property access. This vulnerability is fixed in 0.8.29.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-367

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sandboxjs

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 6 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 4 mentions (2026-02-06); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
sandboxjs

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-02-06: 4Mentions · 2026-02-08: 1Mentions · 2026-02-09: 1PoC Mentioned / Linked · 2026-02-08: 1Exploit Tool / Code · 2026-02-08: 1Patch / Workaround · 2026-02-06: 2Patch / Workaround · 2026-02-09: 1Technical Details · 2026-02-06: 4Technical Details · 2026-02-08: 1Technical Details · 2026-02-09: 102-0602-0802-09
Signal classification3 categories
Disclosure
350.0%
Patch
233.3%
Exploit
116.7%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-02-064
Disclosure2Patch2
2026-02-081
Exploit1
2026-02-091
Disclosure1
Full discourse6 posts
  • Mr. OS@ksg93rd
    Exploit

    #exploit 1⃣. CVE-2025-11730: RCE via DDNS configuration in ZYXEL ATP/USG Series https://github.com/rainpwn/exploits/blob/main/zyxel/rainpwn_cve-2025-11730_ddns_rce.py ]-> PoC https://rainpwn.blog/blog/cve-2025-11730 2⃣. A Deep Dive into CVE-2026-25049: n8n RCE https://blog.securelayer7.net/cve-2026-25049 3⃣. The RCE that AMD won’t fix https://web.archive.org/web/20260205155934/https://mrbruh.com/amd 4⃣. CVE-2026-24858: Fortinet FortiCloud SSO Admin Bypass https://github.com/absholi7ly/CVE-2026-24858-FortiCloud-SSO-Authentication-Bypass 5⃣. CVE-2026-25587, CVE-2026-25641: SandboxJS Sandbox Escape https://github.com/advisories/GHSA-66h4-qj4x-38xp

    Post summary

    The post lists multiple CVEs with linked PoC scripts and exploit code, indicating that functional exploits are available, but it does not mention active exploitation or patches.

    13025131.2K
    3.1K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25641 SandboxJS is a JavaScript sandboxing library. Prior to 0.8.29, there is a sandbox escape vulnerability due to a mismatch between the key on which the validation is pe… https://www.cve.org/CVERecord?id=CVE-2026-25641

    Post summary

    The post announces CVE‑2026‑25641 affecting SandboxJS prior to 0.8.29, noting a sandbox escape flaw caused by key‑validation mismatch, but offers no PoC, exploit, patch, or evidence of active exploitation.

    00010205
    56.5K followersView on X
  • PurpleOps@PurpleOps_io
    Disclosure

    🔍 𝐂𝐨𝐝𝐞 𝐑𝐞𝐝: 𝟒 𝐂𝐫𝐢𝐭𝐢𝐜𝐚𝐥 𝐒𝐚𝐧𝐝𝐛𝐨𝐱𝐉𝐒 𝐅𝐥𝐚𝐰𝐬 (𝐂𝐕𝐒𝐒 𝟏𝟎.𝟎) 𝐀𝐥𝐥𝐨𝐰 𝐇𝐨𝐬𝐭 𝐓𝐚𝐤𝐞𝐨𝐯𝐞𝐫 • Four critical vulnerabilities (CVE-2026-25520, CVE-2026-25586, CVE-2026-25587, CVE-2026-25641) were found in SandboxJS. • All flaws carry a maximum CVSS score of 10.0, enabling host takeover. • SandboxJS versions 0.8.28 and earlier are affected; version 0.8.29 contains the patch. Four critical SandboxJS vulnerabilities, rated CVSS 10.0, allow attackers to bypass security and execute code on the host system.

    Post summary

    Four critical vulnerabilities (CVE‑2026‑25520, ‑25586, ‑25587, ‑25641) in SandboxJS allow host takeover; a patch is available in version 0.8.29.

    0000063
    64 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-25641: CRITICAL] SandboxJS prior to version 0.8.29 had a vulnerability allowing sandbox escapes due to a key validation mismatch. Update to version 0.8.29 to fix this security issue.#cve,CVE-2026-25641,#cybersecurity https://cvefind.com/CVE-2026-25641

    Post summary

    SandboxJS before version 0.8.29 is vulnerable to sandbox escapes caused by a key validation mismatch; applying the 0.8.29 update mitigates the risk.

    0000050
    583 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-25641 - Critical SandboxJS is a JavaScript sandboxing library. Prior to 0.8.29, there is a sandbox escape vulnerability due to a mismatch between the key on which the validation is performed and the key u... https://www.thehackerwire.com/vulnerability/CVE-2026-25641/ https://t.co/CqiOX18CFK

    Post summary

    CVE-2026-25641 is a critical sandbox escape vulnerability in SandboxJS (versions <0.8.29) caused by a validation key mismatch; the tweet announces the issue without providing PoC, exploit, or patch details.

    0000046
    113 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    Nyariv SandboxJS is vulnerable to a critical sandbox escape (CVE-2026-25641) via a TOCTOU bug. Update to 0.8.29 for a fix. #NyarivSandboxJS #SandboxEscape #InfoSec https://www.pulsepatch.io/posts/cve-2026-25641-nyariv-sandboxjs-sandbox-escape

    Post summary

    CVE-2026-25641 is a critical sandbox escape in Nyariv SandboxJS caused by a TOCTOU bug; version 0.8.29 provides a fix.

    0000045
    1 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnyarivsandboxjs-node.js-

Explore more