CVE-2026-25881Disclosure(nyariv / sandboxjs)

LOWCVSS 10.0 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch nyariv sandboxjs systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

SandboxJS is a JavaScript sandboxing library. Prior to 0.8.31, a sandbox escape vulnerability allows sandboxed code to mutate host built-in prototypes by laundering the isGlobal protection flag through array literal intermediaries. When a global prototype reference (e.g., Map.prototype, Set.prototype) is placed into an array and retrieved, the isGlobal taint is stripped, permitting direct prototype mutation from within the sandbox. This results in persistent host-side prototype pollution and may enable RCE in applications that use polluted properties in sensitive sinks (example gadget: execSync(obj.cmd)). This vulnerability is fixed in 0.8.31.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1321

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sandboxjs

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 13 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 12 signals
  • Disclosure: 8 classified signals
  • Peaked 5d ago at 4 mentions (2026-02-10); latest day: 1
  • 13 total mentions across 7 days

Affected systems

Vendors
Products
sandboxjs

Deep dive

Activity timeline13 mentions / 7d
01234Mentions · 2026-02-09: 2Mentions · 2026-02-10: 4Mentions · 2026-02-11: 2Mentions · 2026-02-12: 2Mentions · 2026-02-13: 1Mentions · 2026-02-19: 1Mentions · 2026-03-20: 1PoC Mentioned / Linked · 2026-02-19: 1Patch / Workaround · 2026-02-09: 1Patch / Workaround · 2026-02-10: 2Patch / Workaround · 2026-02-12: 1Patch / Workaround · 2026-02-13: 1Technical Details · 2026-02-09: 2Technical Details · 2026-02-10: 4Technical Details · 2026-02-11: 1Technical Details · 2026-02-12: 2Technical Details · 2026-02-13: 1Technical Details · 2026-02-19: 1Technical Details · 2026-03-20: 102-0902-1002-1102-1202-1302-1903-20
Signal classification3 categories
Disclosure
861.5%
Patch
430.8%
PoC
17.7%
Referenced assets13 URLs
Classification over time
DateTotalLabels
2026-02-092
Disclosure1Patch1
2026-02-104
Disclosure2Patch2
2026-02-112
Disclosure2
2026-02-122
Disclosure1Patch1
2026-02-131
Disclosure1
2026-02-191
PoC1
2026-03-201
Disclosure1
Full discourse13 posts
  • iototsecnews@iototsecnews
    PoC

    SandboxJS の脆弱性 CVE-2026-25881 が FIX:リモート経由でのホスト奪取の恐れと PoC の公開 https://iototsecnews.jp/2026/02/11/critical-sandboxjs-vulnerability-allows-remote-host-takeover-poc-released/ JavaScript を安全な隔離環境で実行するためのライブラリ SandboxJS において、その制限を突破してホストシステムでの操作を許してしまう深刻な脆弱性が発見されました。この問題の原因は、このライブラリにおいて、隔離された環境とホスト・システムを区別するために使用していた保護フラグが、配列操作などの特定の条件下で剥がれ落ちてしまう設計上の不備にあります。本来であれば、隔離環境の中からは外側の重要なオブジェクト (Map や Set など) の書き換えが防止されていますが、このフラグが消失することで、プロトタイプ汚染という手法を用いる攻撃者は、外側のシステムの動作を恒久的に書き換えることが可能になります。ご利用のチームは、ご注意ください。 #CVE202625881 #SandboxJS #Vulnerability

    Post summary

    CVE‑2026‑25881, a serious SandboxJS vulnerability enabling remote host takeover, has been disclosed with a publicly released PoC; technical details of the prototype‑pollution flaw are provided, but no patch, workaround, or evidence of active exploitation is mentioned.

    01000130
    484 followersView on X
  • NerdieNews@NewsNerdie
    Disclosure

    Today's Top Cybersecurity News – February 13, 2026 1. Critical WPvivid Backup Flaw (CVSS 9.8) Exposes 800K WordPress Sites A critical vulnerability (CVE-2026-1357) in the WPvivid Backup plugin affects over 800,000 WordPress sites, potentially exposing sensitive backup data. This flaw poses a significant risk of data compromise and site integrity loss if exploited. Sources: Bleepingcomputer, Cvefeed, Darkreading, Feedburner, Gbhackers, Infosecurity-Magazine, Intel471, Malwarebytes, Mandiant, Proofpoint, Securityweek, Therecord https://securityonline.info/null-byte-nightmare-critical-wpvivid-backup-flaw-cvss-9-8-exposes-800k-wordpress-sites/ 2. Critical SandboxJS Vulnerability (CVE-2026-25881) Enables Host Takeover A critical flaw in SandboxJS allows attackers to escape the sandbox environment and execute malicious code on the host system. This vulnerability poses a severe risk to applications relying on SandboxJS for secure JavaScript execution. Sources: Cvefeed, Microsoft https://securityonline.info/sandbox-breakout-critical-sandboxjs-flaw-cve-2026-25881-allows-host-takeover/ 3. Multiple High and Critical Vulnerabilities Including Authentication Bypass, Buffer Overflows, and Path Traversal A series of critical and high-severity vulnerabilities have been disclosed affecting various software products including PRO-7070, OwnCloud, SpotAuditor, and others. These vulnerabilities enable attackers to bypass authentication, execute arbitrary code via buffer overflows and stack overflows, perform path traversal to access sensitive files, and disclose usernames, posing significant risks to affected systems. Immediate patching and mitigation are recommended to prevent unauthorized access and potential system compromise. Sources: Cvefeed https://cvefeed.io/vuln/detail/CVE-2019-25335 4. Multiple Critical Vulnerabilities in CIPPlanner CIPAce Allow Privilege Escalation and Arbitrary File Access CIPPlanner CIPAce versions before 9.17 contain multiple severe vulnerabilities including account privilege escalation, unauthorized file download, and arbitrary file upload of executable files. These flaws enable low-privileged authenticated users to escalate privileges, access unauthorized files, and potentially execute malicious code, posing significant security risks. Sources: Cvefeed, Feedburner, Securityaffairs https://cvefeed.io/vuln/detail/CVE-2024-50619 5. Critical Authentication Bypass Vulnerabilities Found in ZLAN5143D Devices Two critical vulnerabilities (CVE-2026-25084 and CVE-2026-24789) affect ZLAN5143D devices, allowing attackers to bypass authentication and remotely change device passwords via unprotected internal URLs and API endpoints. These flaws expose devices to unauthorized access and control, posing significant security risks. Sources: Cvefeed https://cvefeed.io/vuln/detail/CVE-2026-25084 Stay sharp. Stay secure. #NerdieNews #InfoSec #CyberSecurity #TechNews #DataSecurity #CyberThreats

    Post summary

    The post reports several critical vulnerabilities across multiple products, providing technical details and urging immediate patching, but offers no PoC, exploit code, or evidence of active exploitation.

    0001056
    54 followersView on X
  • Komodo Cyber Security@Komodosec
    Disclosure

    #VulnerabilityReport #ArrayTaintBypass Sandbox Breakout: Critical SandboxJS Flaw (CVE-2026-25881) Allows Host Takeover https://securityonline.info/sandbox-breakout-critical-sandboxjs-flaw-cve-2026-25881-allows-host-takeover/?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    The tweet reports a new critical SandboxJS vulnerability (CVE-2026-25881) that could lead to host takeover, but offers only high‑level details, with no PoC, exploit code, patch, or evidence of active exploitation.

    0000041
    1.5K followersView on X
  • The Daily Tech Feed@dailytechonx
    Patch

    Critical SandboxJS vulnerability (CVE-2026-25881) allows remote code execution via prototype pollution. Update to version 0.8.31 immediately to secure your applications. Link: https://thedailytechfeed.com/critical-sandboxjs-flaw-allows-remote-code-execution-cve-2026-25881-patched-in-update-0-8-31/ #Security #Vulnerability #Update #Software #Hacking #Exploit #Patch #Protection #Alert #Technology #Code #Remote #Execution #Pollution #Version #Bug #Fix #Risk #Threat #Safety

    Post summary

    CVE-2026-25881, a prototype pollution-based remote code execution flaw in SandboxJS, is mitigated by updating to version 0.8.31.

    0000046
    233 followersView on X
  • キタきつね@foxbook
    Disclosure

    サンドボックスブレイクアウト:重大なSandboxJSの脆弱性(CVE-2026-25881)によりホストの乗っ取りが可能に Sandbox Breakout: Critical SandboxJS Flaw (CVE-2026-25881) Allows Host Takeover #DailyCyberSecurity (Feb 11) https://securityonline.info/sandbox-breakout-critical-sandboxjs-flaw-cve-2026-25881-allows-host-takeover/

    Post summary

    The tweet announces the discovery of a critical SandboxJS vulnerability (CVE‑2026‑25881) that enables host takeover, but it does not provide a PoC, exploit code, patch, or evidence of active exploitation.

    00000227
    4.7K followersView on X
  • CrowdCyber 🌐@CrowdCyber_Com
    Disclosure

    Sandbox Breakout: Critical SandboxJS Flaw (CVE-2026-25881) Allows Host Takeover https://securityonline.info/sandbox-breakout-critical-sandboxjs-flaw-cve-2026-25881-allows-host-takeover/

    Post summary

    The article announces a new critical SandboxJS vulnerability (CVE‑2026‑25881) that could enable host takeover, but provides no further technical details or evidence of exploitation.

    0000044
    298 followersView on X
  • Karma-X@Karma_X_Inc
    Disclosure

    Sandbox Breakout: Critical SandboxJS Flaw (CVE-2026-25881) Allows Host Takeover https://securityonline.info/sandbox-breakout-critical-sandboxjs-flaw-cve-2026-25881-allows-host-takeover/

    Post summary

    The article announces a critical SandboxJS flaw (CVE‑2026‑25881) that enables a sandbox breakout and host takeover, but no PoC, exploit, or patch details are provided.

    0000051
    73 followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Critical host-side prototype pollution in #SandboxJS CVE-2026-25881 CVSS: 9.0 A remote, unauthenticated attacker can escape the sandbox without user interaction and execute code remotely #RCE Update to 0.8.31 or later #Patch #Patch #Patch

    Post summary

    The post alerts about a critical prototype pollution vulnerability (CVE‑2026‑25881) and directs users to apply the 0.8.31 patch to mitigate the remote code execution risk.

    00000169
    7.2K followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    Nyariv SandboxJS is vulnerable to host prototype pollution enabling sandbox escape (CVE-2026-25881). Update to 0.8.31+ for #JavaScript #security. https://www.pulsepatch.io/posts/cve-2026-25881-nyariv-sandboxjs-prototype-pollution

    Post summary

    Nyariv SandboxJS suffers from a prototype pollution vulnerability (CVE-2026-25881) that can lead to sandbox escape. Updating to 0.8.31+ addresses the issue.

    0000045
    1 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25881 Prototype Pollution Vulnerability in SandboxJS Prior to 0.8.31 Enabling RCE https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25881

    Post summary

    The post announces a prototype‑pollution flaw in SandboxJS that can lead to RCE, providing the CVE identifier and a link to details, but no PoC, exploit, or patch information.

    0000068
    4.0K followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-25881: Dirty Laundry: Escaping SandboxJS via Array Laundering A critical sandbox escape vulnerability in `@nyariv/sandboxjs` allows malicious code to bypass the 'isGlobal' protection flag by laundering host references through array literals. ... https://cvereports.com/reports/CVE-2026-25881

    Post summary

    The post announces a critical sandbox escape vulnerability in @nyariv/sandboxjs, explaining that malicious code can bypass the 'isGlobal' protection flag via array laundering.

    0000051
    27 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-25881: CRITICAL] JavaScript sandboxing library, SandboxJS, fixed a critical vulnerability in version 0.8.31 that allowed sandboxed code to escape and mutate host built-in prototypes, potentially le...#cve,CVE-2026-25881,#cybersecurity https://cvefind.com/CVE-2026-25881

    Post summary

    CVE-2026-25881 is a critical SandboxJS vulnerability that permits sandbox escape and prototype mutation; the issue was addressed in the 0.8.31 release.

    0000063
    583 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25881 SandboxJS is a JavaScript sandboxing library. Prior to 0.8.31, a sandbox escape vulnerability allows sandboxed code to mutate host built-in prototypes by laundering t… https://www.cve.org/CVERecord?id=CVE-2026-25881

    Post summary

    The text briefly announces a sandbox escape flaw in SandboxJS (prior to 0.8.31) that lets sandboxed code alter host prototypes, but it does not provide PoC, exploit, patch, or active exploitation information.

    00000215
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnyarivsandboxjs-node.js-

Explore more