CVE-2026-34208Disclosure(nyariv / sandboxjs)

LOWCVSS 10.0 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch nyariv sandboxjs systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

SandboxJS is a JavaScript sandboxing library. Prior to 0.8.36, SandboxJS blocks direct assignment to global objects (for example Math.random = ...), but this protection can be bypassed through an exposed callable constructor path: this.constructor.call(target, attackerObject). Because this.constructor resolves to the internal SandboxGlobal function and Function.prototype.call is allowed, attacker code can write arbitrary properties into host global objects and persist those mutations across sandbox instances in the same process. This vulnerability is fixed in 0.8.36.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-693CWE-915

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sandboxjs

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 12 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 9 signals
  • Disclosure: 6 classified signals
  • General: 3 classified signals
  • Peaked 3d ago at 3 mentions (2026-04-07); latest day: 1
  • 12 total mentions across 6 days

Affected systems

Vendors
Products
sandboxjs

Deep dive

Activity timeline12 mentions / 6d
01223Mentions · 2026-04-04: 1Mentions · 2026-04-06: 2Mentions · 2026-04-07: 3Mentions · 2026-04-08: 2Mentions · 2026-04-09: 3Mentions · 2026-04-14: 1PoC Mentioned / Linked · 2026-04-06: 1PoC Mentioned / Linked · 2026-04-09: 2Patch / Workaround · 2026-04-06: 1Patch / Workaround · 2026-04-07: 1Patch / Workaround · 2026-04-08: 1Patch / Workaround · 2026-04-09: 1Patch / Workaround · 2026-04-14: 1Technical Details · 2026-04-04: 1Technical Details · 2026-04-06: 2Technical Details · 2026-04-07: 1Technical Details · 2026-04-08: 1Technical Details · 2026-04-09: 3Technical Details · 2026-04-14: 104-0404-0604-0704-0804-0904-14
Signal classification3 categories
Disclosure
650.0%
Patch
325.0%
General
325.0%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-04-041
Disclosure1
2026-04-062
Disclosure1Patch1
2026-04-073
General2Patch1
2026-04-082
Disclosure1General1
2026-04-093
Disclosure3
2026-04-141
Patch1
Full discourse12 posts
  • Gray Hats@the_yellow_fall
    Disclosure

    CVE-2026-34208: A critical 10.0 flaw in SandboxJS allows code to escape and poison host objects like Math.random. Secure your environment—update immediately! #SandboxJS #InfoSec #CyberSecurity #Javascript #WebDev #BugBounty #CVE202634208 #SandboxEscape https://securityonline.info/sandboxjs-escape-vulnerability-cve-2026-34208-host-poisoning/ https://t.co/I4oCgHPdh2

    Post summary

    The post announces a critical 10.0 sandbox escape vulnerability in SandboxJS that can poison host objects, urges immediate update, but does not provide PoC, exploit details, or evidence of active exploitation.

    05182643
    12.3K followersView on X
  • Misbar | مسبار@MisbarSec
    Disclosure

    📌 ثغرة SandboxJS (CVE-2026-34208) بدرجة خطورة CVSS 10 كشف تقرير أمني عن ثغرة حرجة (CVE-2026-34208) في SandboxJS، تحمل تصنيف CVSS 10، وتتيح للمهاجمين تجاوز البيئة المعزولة (Sandbox Escape). تمكن هذه الثغرة التعليمات البرمجية غير الموثوقة من اختراق نظام المضيف والتسبب في "host poisoning". تشكل هذه القدرة تهديداً مباشراً لسلامة الأنظمة التي تعتمد على SandboxJS لعزل التعليمات البرمجية. يُنصح المطورون والمشغلون بمراقبة التحديثات الأمنية وتطبيق التصحيحات فور توفرها لدرء الاستغلال المحتمل. 🔗 للمزيد: https://securityonline.info/sandboxjs-escape-vulnerability-cve-2026-34208-host-poisoning/

    Post summary

    The post announces a critical SandboxJS sandbox escape vulnerability (CVS 10, CVE‑2026‑34208) that can lead to host poisoning, and advises that patches be applied as soon as they are released.

    00040962
    245 followersView on X
  • Threat@THREATCHAIN
    General

    🚨 CVE-2026-34208: JavaScript Sandbox Library Can't Keep Attackers Out What CVE-2026-34208 is, how it works, and how to defend against it. https://threatchain.io/cve-2026-34208-javascript-sandbox-library-can-t-keep-attackers-out-81071546 #infosec #malware #threatintel

    Post summary

    The tweet announces CVE-2026-34208 and points to an external article for details but provides no evidence of a PoC, exploit, active attacks, patch, or technical specifics.

    11020111
    19 followersView on X
  • Mr. OS@ksg93rd
    Disclosure

    #AppSec 1⃣ RCE in the Electron desktop client via stored XSS in synced table captions https://github.com/advisories/GHSA-phhp-9rm9-6gr2 // Critical CVE-2026-39846, 9.1/10 2⃣ GhidraServer PKI User Impersonation via Null Signature https://github.com/califio/publications/tree/main/MADBugs/ghidra-server // Null-signature flaw in GhidraServer's PKI authentication module allows any user with a valid CA-signed certificate to impersonate any other user on the server 3⃣ SandboxJS: Sandbox integrity escape https://github.com/advisories/GHSA-2gg9-6p7w-6cpj // Critical CVE-2026-34208, 10/10

    Post summary

    The tweet announces three newly disclosed critical vulnerabilities, linking to GitHub advisories, and provides technical details but no evidence of active exploitation, patches, or exploit tools.

    00011218
    3.2K followersView on X
  • Firmis Labs@FirmisLabs
    Patch

    CVE-2026-34208 · NIST 10.0/10 https://nvd.nist.gov/vuln/detail/CVE-2026-34208 ask your AI: "check if my project uses SandboxJS and if it's below version 0.8.36" then: "update SandboxJS to version 0.8.36 or later and make sure my sandboxed code execution still works"

    Post summary

    The note references CVE-2026-34208 with a CVSS of 10.0 and advises updating SandboxJS to 0.8.36 or newer, offering a workaround but showing no exploit or active usage details.

    1000032
    1 followersView on X
  • Michael Martino@battista212
    Patch

    CISA published HIGH severity vulnerabilities including CVE-2026-34208 (CVSS 10) for SandboxJS unsafe deserialization enabling arbitrary code execution. If you're running affected systems, patch now.

    Post summary

    CISA alerts about CVE‑2026‑34208, a high‑severity unsafe deserialization flaw in SandboxJS that could enable arbitrary code execution, and advises affected users to apply patches immediately.

    0000027
    199 followersView on X
  • キタきつね@foxbook
    Disclosure

    CVE-2026-34208 (CVSS 10): SandboxJSで重大なサンドボックス脱出の脆弱性が発見されました CVE-2026-34208 (CVSS 10): Critical Sandbox Escape Uncovered in SandboxJS #DailyCyberSecurity (Apr 8) https://securityonline.info/sandboxjs-escape-vulnerability-cve-2026-34208-host-poisoning/

    Post summary

    CVE‑2026‑34208 is reported as a critical sandbox‑escape flaw (CVSS 10) in SandboxJS, with PoC information linked but no evidence of active exploitation, patch, or mitigation steps.

    00000249
    4.9K followersView on X
  • Abdulaziz Alharbi@Alharbi_Abz
    General

    :اليومي CVE ملخص ال 🔴 CVE-2025-54328 [Samsung Mobile Processor] 🔴 CVE-2026-34208 [SandboxJS library prior to 0.8.36] 🔴 CVE-2026-5734 [Firefox < 149.0.2] 🔴 CVE-2026-0740 [WordPress sites using Ninja Forms - File Uploads plugin version 3.3.26 or lower] #CVE #Cybersecurity

    Post summary

    A short list of four CVEs with affected products is presented, but no additional technical details, PoCs, or mitigation information are included.

    00000294
    581 followersView on X
  • CTIWatch@ctiwatchcloud
    General

    🔍 Today's Top Vulnerabilities 🔴 CVE-2026-34208 | CVSS 10.0 🔴 CVE-2026-34976 | CVSS 10.0 🔴 CVE-2025-54328 | CVSS 10.0 🔗 http://ctiwatch.cloud/vulnerabilities #CVE #Vulnerability #ThreatIntel

    Post summary

    The tweet lists three high-severity CVEs with their CVSS scores, but provides no additional technical, exploit, or mitigation details.

    00000208
    5.6K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-34208: CRITICAL] JavaScript sandboxing library SandboxJS version 0.8.36 addresses a vulnerability allowing attackers to bypass protections and write arbitrary properties into host global objects.#cve,CVE-2026-34208,#cybersecurity https://cvefind.com/CVE-2026-34208

    Post summary

    The tweet highlights a critical CVE in SandboxJS and notes that version 0.8.36 fixes the flaw that allows bypassing sandbox protections to write arbitrary host global object properties, but gives no evidence of exploitation or a PoC.

    0000036
    619 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-34208: SandboxJS: Sandbox integrity esc... JavaScript sandbox escape via http://constructor.call() bypasses global object protection—perfect 10.0 CVSS for a reason, this... https://zerodaysignal.com/vulnerability/CVE-2026-34208 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE‑2026‑34208, explains it as a JavaScript sandbox escape via constructor.call() with a 10.0 CVSS score, and links to an external page for further details.

    0000054
    204 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A critical sandbox integrity escape (CVE-2026-34208) has been identified in `SandboxJS`, potentially allowing for arbitrary code execution outside the sandbox. Review your deployments. #infosec #javascript #sandbox https://www.pulsepatch.io/posts/cve-2026-34208-sandboxjs-integrity-escape

    Post summary

    An announcement of a critical sandbox escape (CVE-2026-34208) in SandboxJS is released, warning that it could permit arbitrary code execution outside the sandbox and urging deployments to review.

    0000057
    11 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnyarivsandboxjs-node.js-

Explore more