
CVE-2026-32723 SandboxJS is a JavaScript sandboxing library. Prior to 0.8.35, SandboxJS timers have an execution-quota bypass. A global tick state (`currentTicks.current`) is shared… https://www.cve.org/CVERecord?id=CVE-2026-32723
Post summary
The text discloses a new execution‑quota bypass vulnerability in SandboxJS timers, providing technical details but no exploit evidence or patch information.

