logo

Critical SandboxJS Vulnerability Allows Remote Host Takeover – PoC Released

ID: 1fd9a9d8-b9fb-5427-a996-adcd6732ce6d

STIX ID: report--1fd9a9d8-b9fb-5427-a996-adcd6732ce6d

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-02-11

Date Updated: 2026-04-21

Author: Abinaya

...
...

**Critical SandboxJS prototype-pollution vulnerability (CVE-2026-25881) enables sandboxed code to strip protection flags from prototype references—leading to persistent host prototype mutation and potential remote code execution; a public PoC demonstrates attacks and developers are urged to upgrade to v0.8.31 and apply mitigations (freeze built-ins, audit use of user-controlled properties).**

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.