CVE-2026-43898Disclosure(nyariv / sandboxjs)

LOWCVSS 10.0 · CRITICAL

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch nyariv sandboxjs systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

SandboxJS is a JavaScript sandboxing library. Prior to 0.9.6, sandbox-defined functions expose Function.caller, allowing sandboxed code to recover the internal LispType.Call runtime callback. That callback can then be invoked with attacker-controlled fake context and obj values to extract blocked host statics, recover the real host Function constructor, and execute arbitrary host JavaScript. This vulnerability is fixed in 0.9.6.

2.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sandboxjs

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 12 mentions across 8 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 12 signals
  • Disclosure: 10 classified signals
  • General: 1 classified signal
  • Peaked 6d ago at 3 mentions (2026-05-13); latest day: 2
  • 12 total mentions across 8 days

Affected systems

Vendors
Products
sandboxjs

Deep dive

Activity timeline12 mentions / 8d
01223Mentions · 2026-05-12: 1Mentions · 2026-05-13: 3Mentions · 2026-05-15: 1Mentions · 2026-05-20: 1Mentions · 2026-05-28: 2Mentions · 2026-05-29: 1Mentions · 2026-06-17: 1Mentions · 2026-06-23: 2PoC Mentioned / Linked · 2026-05-20: 1Patch / Workaround · 2026-05-13: 1Technical Details · 2026-05-12: 1Technical Details · 2026-05-13: 3Technical Details · 2026-05-15: 1Technical Details · 2026-05-20: 1Technical Details · 2026-05-28: 2Technical Details · 2026-05-29: 1Technical Details · 2026-06-17: 1Technical Details · 2026-06-23: 205-1205-1305-1505-2005-2805-2906-1706-23
Signal classification3 categories
Disclosure
1083.3%
General
18.3%
Patch
18.3%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-05-121
Disclosure1
2026-05-133
Disclosure1General1Patch1
2026-05-151
Disclosure1
2026-05-201
Disclosure1
2026-05-282
Disclosure2
2026-05-291
Disclosure1
2026-06-171
Disclosure1
2026-06-232
Disclosure2
Full discourse12 posts
  • elhacker.NET@elhackernet
    Disclosure

    Vulnerabilidad crítica de SandboxJS permite tomar el control del host Se ha descubierto una falla de seguridad crítica en SandboxJS , una biblioteca de aislamiento de JavaScript muy utilizada en npm CVE-2026-43898, puntuación de gravedad máxima de 10.0 https://blog.elhacker.net/2026/05/vulnerabilidad-critica-de-sandboxjs.html

    Post summary

    The post announces a critical SandboxJS vulnerability (CVE‑2026‑43898) with a maximum severity score of 10.0 that permits host takeover, but it provides no details on exploitation, PoC, or patch availability.

    0802251.7K
    140.9K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Critical Alert: CVE-2026-43898 (CVSS 10) in SandboxJS allows a total sandbox escape and RCE. Update to version 0.9.6 immediately to secure your host. #SandboxJS #CyberSecurity #InfoSec #RCE #VulnerabilityAlert #JavaScript #WebSecurity #CVE #Coding https://securityonline.info/sandboxjs-vulnerability-cve-2026-43898-rce-escape/ https://t.co/j2TzzCWfrm

    Post summary

    The post highlights a critical CVE-2026-43898 in SandboxJS that enables sandbox escape and RCE, and urges users to upgrade to version 0.9.6 to secure their environment.

    01061552
    12.5K followersView on X
  • Directoratul Național de Securitate Cibernetică@DNSC_RO
    Disclosure

    🚨 ALERTĂ - vulnerabilitate critică în biblioteca SandboxJS (CVE-2026-43898, scor 10/10) ⚠️ Poate permite acces neautorizat la informații interne ale funcțiilor din sandbox 👉 https://www.dnsc.ro/citeste/alerta-vulnerabilitate-critica-in-biblioteca-sandboxjs #DNSC https://t.co/5WuOXIQtb2

    Post summary

    A critical CVE-2026-43898 in the SandboxJS library is reported with a 10/10 severity score, potentially allowing unauthorized internal sandbox access, but no PoC, exploit, or patch information is disclosed.

    01020138
    4.7K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-43898: SandboxJS Critical RCE — Function.caller Leaks Sandbox Internals SandboxJS, with 50K weekly npm downloads, is used by developers to safely execute third-party JavaScript in both Node.js and browser environments.

    Post summary

    The snippet announces a critical RCE in SandboxJS caused by a Function.caller leak that exposes internals, representing a vulnerability disclosure.

    1000061
    295 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-43898 · 9.8 → v3.11.2 CVE-2026-43898: SandboxJS Critical RCE — Function.caller Leaks Sandbox Internals

    Post summary

    The snippet announces a critical remote code execution flaw in SandboxJS (CVE‑2026‑43898) with a CVSS of 9.8, highlighting internals leakage via Function.caller, but provides no PoC, exploit, or patch information.

    1000062
    295 followersView on X
  • Joey Romaine 🇺🇸 |=★=|@Tank23x0
    Disclosure

    New advisory to triage: CVE-2026-43898. SandboxJS has a sandbox escape via Function.caller leakage of internal call op Inventory first. Panic never helps.

    Post summary

    The advisory announces CVE-2026-43898 as a sandbox escape in SandboxJS caused by Function.caller leakage of internal call operations.

    1000041
    337 followersView on X
  • CVE Brief@DailyCVEBrief
    Disclosure

    DEEP DIVE — CVE-2026-43898 dropped this week: a sandbox escape in SandboxJS (@nyariv/sandboxjs <=0.9.5). Untrusted JS abuses Function.caller to break out and run on the host. CVSS 10.0, no auth. Check: npm ls @nyariv/sandboxjs https://t.co/pwTbfK2Iz8

    Post summary

    The post announces CVE‑2026‑43898, a high‑severity sandbox escape in SandboxJS (<=0.9.5) caused by abuse of Function.caller, without providing patches, exploit details, or evidence of active usage.

    1000082
    18 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-43898 SandboxJS is a JavaScript sandboxing library. Prior to 0.9.6, sandbox-defined functions expose Function.caller, allowing sandboxed code to recover the internal LispTy… https://www.cve.org/CVERecord?id=CVE-2026-43898

    Post summary

    The post documents CVE-2026-43898, stating that SandboxJS versions before 0.9.6 expose Function.caller in sandboxed functions, enabling recovery of internal LispTy. No PoC, exploit code, active exploitation, or patch information is presented.

    00010208
    57.5K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    SandboxJS Escape の脆弱性は CVE-2026-43898 が FIX:ホスト上での任意のコード実行と PoC https://iototsecnews.jp/2026/05/13/critical-sandboxjs-escape-vulnerability-enables-host-takeover/ JavaScript のサンドボックス用ライブラリ SandboxJS に見つかった、きわめて深刻な脆弱性を解説する記事です。 問題の原因は、サンドボックス内の関数が、ホスト側の内部機能 (http://LispType.Call) を呼び出せる状態で放置されていたことにあります。特定のプロパティ (caller) を介して、この内部機能を盗み出した攻撃者は、 隔離された環境を突破してホストシステム上で任意のコマンドを実行するサンドボックス・エスケープを達成します。 きわめて危険な脆弱性であり、PoC も提供されているため、ご利用のチームは、ご注意ください。 #CVE202643898 #Escape #PoC #SandboxJS #Vulnerability

    Post summary

    The post announces CVE‑2026‑43898, a sandbox escape that allows arbitrary command execution on the host, provides a PoC, and warns security teams to be vigilant.

    01000158
    489 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-43898 Arbitrary Code Execution in SandboxJS via Function.caller Exposure Befor... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-43898 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    The post announces CVE-2026-43898, describing it as an arbitrary code execution vulnerability in SandboxJS through Function.caller exposure, but provides no PoC, exploit, or patch details.

    0000069
    4.0K followersView on X
  • まきまっきー@yfmaki
    General

    SandboxJSの致命的欠陥、CVE-2026-43898 CVSS10とかびっくりするな

    Post summary

    A brief tweet noting a CVE (CVE-2026-43898) with a CVSS score of 10, without further technical or exploitation details.

    0000029
    414 followersView on X
  • Vulert@vulert_official
    Disclosure

    🚨 Critical @nyariv/sandboxjs Vulnerability — CVE-2026-43898 Attackers may escape the sandbox and execute arbitrary code remotely ⚠️ 🔗 https://vulert.com/vuln-db/CVE-2026-43898 #CyberSecurity #RCE #NodeJS #CVE2026 #DevSecOps #SecurityAlert https://t.co/ytrjikBc6U

    Post summary

    The tweet alerts that CVE-2026-43898 is a critical sandbox escape vulnerability in @nyariv/sandboxjs, allowing remote code execution, and links to a database entry for more details.

    0000010
    125 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnyarivsandboxjs-node.js-

Explore more