CVE-2026-26954Disclosure(nyariv / sandboxjs)

LOWCVSS 10.0 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch nyariv sandboxjs systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

SandboxJS is a JavaScript sandboxing library. Prior to 0.8.34, it is possible to obtain arrays containing Function, which allows escaping the sandbox. Given an array containing Function, and Object.fromEntries, it is possible to construct {[p]: Function} where p is any constructible property. This vulnerability is fixed in 0.8.34.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sandboxjs

Threat summary

  • Patch or workaround signal is available
  • 10 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 10 signals
  • Disclosure: 6 classified signals
  • Peaked 1d ago at 3 mentions (2026-03-16); latest day: 3
  • 10 total mentions across 4 days

Affected systems

Vendors
Products
sandboxjs

Deep dive

Activity timeline10 mentions / 4d
01223Mentions · 2026-03-13: 2Mentions · 2026-03-14: 2Mentions · 2026-03-16: 3Mentions · 2026-03-17: 3Patch / Workaround · 2026-03-13: 1Patch / Workaround · 2026-03-16: 1Patch / Workaround · 2026-03-17: 3Technical Details · 2026-03-13: 2Technical Details · 2026-03-14: 2Technical Details · 2026-03-16: 3Technical Details · 2026-03-17: 303-1303-1403-1603-17
Signal classification2 categories
Disclosure
660.0%
Patch
440.0%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-132
Disclosure1Patch1
2026-03-142
Disclosure2
2026-03-163
Disclosure2Patch1
2026-03-173
Disclosure1Patch2
Full discourse10 posts
  • Gray Hats@the_yellow_fall
    Patch

    Critical 10.0 CVSS flaw in SandboxJS (CVE-2026-26954) allows attackers to escape the sandbox and achieve Remote Code Execution. Patch to version 0.8.34 now. #SandboxJS #CVE #CyberSecurity #InfoSec #JavaScript #NodeJS #Vulnerability #PatchAlert #RCE https://securityonline.info/golden-ticket-critical-10-cvss-sandboxjs-flaw-cve-2026-26954-rce/ https://t.co/JGOVKkLmYb

    Post summary

    The CVE-2026-26954 RCE flaw in SandboxJS is a critical vulnerability (CVSS 10.0) and a patch (v0.8.34) is available.

    0110153921
    10.7K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Critical code injection vulnerability in the #SandboxJS JavaScript library. CVE-2026-26954 CVSS: 10.0 Exploitation can lead to sandbox escape. More info: https://github.com/nyariv/SandboxJS/security/advisories/GHSA-6r9f-759j-hjgv #Patch #Patch #Patch

    Post summary

    A critical code injection flaw (CVE‑2026‑26954) in SandboxJS with CVSS 10.0 has been disclosed, and a patch is referenced in the accompanying advisory.

    01041369
    7.2K followersView on X
  • Misbar | مسبار@MisbarSec
    Disclosure

    📌 ثغرة عالية الخطورة تهدد خوادم LiteSpeed Web Server عبر حقن (OS Command Injection) أصدرت JPCERT/CC تحذيراً أمنياً حرجاً بشأن ثغرة عالية الخطورة (CVSS 8.6) في خوادم الويب LiteSpeed Web Server، البديل الشائع لخادم Apache. تستغل هذه الثغرة، المحددة بـ CVE-2026-31386 و CVE-2026-26954، ضعفاً في حقن أوامر نظام التشغيل (OS Command Injection). يتيح هذا الضعف للمهاجمين تنفيذ تعليمات برمجية عن بُعد على الخوادم المستهدفة، مما قد يؤدي إلى السيطرة الكاملة عليها. يُنصح بشدة لمسؤولي الأنظمة بتطبيق التحديثات الأمنية فوراً للتخفيف من مخاطر الاستغلال المحتملة. 🔗 للمزيد: https://securityonline.info/server-siege-critical-8-6-cvss-flaw-litespeed-web-server-os-command-injection/

    Post summary

    The advisory announces two high‑severity OS command injection CVEs in LiteSpeed Web Server, describing their impact and urging administrators to install updates.

    00030468
    71 followersView on X
  • kokumօtօ@__kokumoto
    Patch

    SandboxJSにCVSSスコア10の脆弱性。CVE-2026-26954はFunctionコンストラクタを含む配列を取得できるもので、セキュリティ制約を突破可能。緊急パッチが出ている。 https://securityonline.info/golden-ticket-critical-10-cvss-sandboxjs-flaw-cve-2026-26954-rce/

    Post summary

    CVE-2026-26954 is a CVSS 10 flaw in SandboxJS that lets attackers bypass security constraints by retrieving arrays with Function constructors; an urgent patch has been released.

    00010660
    7.3K followersView on X
  • CrowdCyber 🌐@CrowdCyber_Com
    Disclosure

    Critical 10.0 CVSS SandboxJS Flaw Grants Complete Remote Code Execution https://securityonline.info/golden-ticket-critical-10-cvss-sandboxjs-flaw-cve-2026-26954-rce/

    Post summary

    The headline introduces a newly disclosed SandboxJS vulnerability with a CVSS score of 10.0 that allows complete remote code execution, but does not provide PoC, exploit code, or mitigation details.

    0000057
    300 followersView on X
  • Karma-X@Karma_X_Inc
    Disclosure

    Critical 10.0 CVSS SandboxJS Flaw Grants Complete Remote Code Execution https://securityonline.info/golden-ticket-critical-10-cvss-sandboxjs-flaw-cve-2026-26954-rce/

    Post summary

    The text announces a critical vulnerability (CVE‑2026‑26954) in SandboxJS with a 10.0 CVSS score that permits full remote code execution, but it lacks details on mitigation, exploitation code, or active attacks.

    0000046
    70 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-26954 - Critical SandboxJS is a JavaScript sandboxing library. Prior to 0.8.34, it is possible to obtain arrays containing Function, which allows escaping the sandbox. Given an array containing Function, ... https://www.thehackerwire.com/vulnerability/CVE-2026-26954/ https://t.co/p54ouoaGDN

    Post summary

    CVE-2026-26954 is a critical vulnerability in SandboxJS allowing sandbox escape via arrays of function objects before version 0.8.34; the text provides technical details but no PoC, exploitation evidence, or patch information.

    0000047
    135 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26954 SandboxJS is a JavaScript sandboxing library. Prior to 0.8.34, it is possible to obtain arrays containing Function, which allows escaping the sandbox. Given an array … https://www.cve.org/CVERecord?id=CVE-2026-26954

    Post summary

    The post discloses a sandbox escape flaw in SandboxJS v0.8.34, explaining the vulnerability mechanism but providing no PoC, exploit code, or patch details.

    0000092
    56.7K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-26954: CRITICAL] Vulnerability in SandboxJS library prior to version 0.8.34 allowed escaping the sandbox by obtaining arrays containing Function. Update to secure your JavaScript sandbox.#cve,CVE-2026-26954,#cybersecurity https://cvefind.com/CVE-2026-26954

    Post summary

    The text announces a critical sandbox escape flaw in SandboxJS versions before 0.8.34 and urges users to update to secure their JavaScript sandbox.

    0000048
    602 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-26954: SandboxJS has a Sandbox Escape (... Array-to-Function constructor chaining breaks SandboxJS containment completely - CVSS 10.0 means full RCE from browser ... https://zerodaysignal.com/vulnerability/CVE-2026-26954 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The text announces CVE-2026-26954 as a high‑severity sandbox escape in SandboxJS, noting a full RCE via Array‑to‑Function constructor chaining, but provides no PoC, exploit, patch, or evidence of active exploitation.

    0000067
    144 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnyarivsandboxjs-node.js-

Explore more