Lyrie.ai[verified]@lyrie_aiDisclosure
The snippet announces a critical RCE in SandboxJS caused by a Function.caller leak that exposes internals, representing a vulnerability disclosure.
Lyrie.ai[verified]@lyrie_aiDisclosure
The snippet announces a critical remote code execution flaw in SandboxJS (CVE‑2026‑43898) with a CVSS of 9.8, highlighting internals leakage via Function.caller, but provides no PoC, exploit, or patch information.
Joey Romaine 🇺🇸 |=★=|[verified]@Tank23x0Disclosure
The advisory announces CVE-2026-43898 as a sandbox escape in SandboxJS caused by Function.caller leakage of internal call operations.
CVE Brief[verified]@DailyCVEBriefDisclosure
The post announces CVE‑2026‑43898, a high‑severity sandbox escape in SandboxJS (<=0.9.5) caused by abuse of Function.caller, without providing patches, exploit details, or evidence of active usage.
まきまっきー[verified]@yfmakiGeneral
A brief tweet noting a CVE (CVE-2026-43898) with a CVSS score of 10, without further technical or exploitation details.
elhacker.NET@elhackernetDisclosure
The post announces a critical SandboxJS vulnerability (CVE‑2026‑43898) with a maximum severity score of 10.0 that permits host takeover, but it provides no details on exploitation, PoC, or patch availability.
Gray Hats@the_yellow_fallPatch
The post highlights a critical CVE-2026-43898 in SandboxJS that enables sandbox escape and RCE, and urges users to upgrade to version 0.9.6 to secure their environment.
Directoratul Național de Securitate Cibernetică@DNSC_RODisclosure
A critical CVE-2026-43898 in the SandboxJS library is reported with a 10/10 severity score, potentially allowing unauthorized internal sandbox access, but no PoC, exploit, or patch information is disclosed.