Critical SandboxJS Vulnerability Allows Remote Host Takeover – PoC Released
ID: 1fd9a9d8-b9fb-5427-a996-adcd6732ce6d
STIX ID: report--1fd9a9d8-b9fb-5427-a996-adcd6732ce6d
Feed Name: cybersecurityNews.com
Threat Score
**Critical SandboxJS prototype-pollution vulnerability (CVE-2026-25881) enables sandboxed code to strip protection flags from prototype references—leading to persistent host prototype mutation and potential remote code execution; a public PoC demonstrates attacks and developers are urged to upgrade to v0.8.31 and apply mitigations (freeze built-ins, audit use of user-controlled properties).**
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
