Misbar | مسبار[verified]@MisbarSecDisclosure
The advisory announces two high‑severity OS command injection CVEs in LiteSpeed Web Server, describing their impact and urging administrators to install updates.
kokumօtօ[verified]@__kokumotoPatch
CVE-2026-26954 is a CVSS 10 flaw in SandboxJS that lets attackers bypass security constraints by retrieving arrays with Function constructors; an urgent patch has been released.
Karma-X[verified]@Karma_X_IncDisclosure
The text announces a critical vulnerability (CVE‑2026‑26954) in SandboxJS with a 10.0 CVSS score that permits full remote code execution, but it lacks details on mitigation, exploitation code, or active attacks.
Gray Hats@the_yellow_fallPatch
The CVE-2026-26954 RCE flaw in SandboxJS is a critical vulnerability (CVSS 10.0) and a patch (v0.8.34) is available.
CCB Alert@CCBalertPatch
A critical code injection flaw (CVE‑2026‑26954) in SandboxJS with CVSS 10.0 has been disclosed, and a patch is referenced in the accompanying advisory.
CrowdCyber 🌐@CrowdCyber_ComDisclosure
The headline introduces a newly disclosed SandboxJS vulnerability with a CVSS score of 10.0 that allows complete remote code execution, but does not provide PoC, exploit code, or mitigation details.
The Hacker Wire@TheHackerWireDisclosure
CVE-2026-26954 is a critical vulnerability in SandboxJS allowing sandbox escape via arrays of function objects before version 0.8.34; the text provides technical details but no PoC, exploitation evidence, or patch information.
CVE@CVEnewDisclosure
The post discloses a sandbox escape flaw in SandboxJS v0.8.34, explaining the vulnerability mechanism but providing no PoC, exploit code, or patch details.