Critical SandboxJS Escape Vulnerability Enables Host Takeover
ID: 1afb2707-78d1-5580-b451-cda4fd0dba06
STIX ID: report--1afb2707-78d1-5580-b451-cda4fd0dba06
Feed Name: cybersecurityNews.com
Threat Score
A critical CVE-2026-43898 sandbox escape in the npm package @nyariv/sandboxjs (≤ 0.9.5) lets sandboxed code leak an internal LispType.Call callback, chain forged calls to obtain the host Function constructor, and achieve full remote code execution on the host. GitHub researchers and the reporter provided a working proof-of-concept; the issue is fixed in version 0.9.6 and users running untrusted JavaScript through affected versions are urged to update immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
