logo

Critical SandboxJS Flaw Enables Host System Takeover

ID: 11e508ab-b4aa-5d89-822e-4f0db17665a2

STIX ID: report--11e508ab-b4aa-5d89-822e-4f0db17665a2

Feed Name: Cyber Press

Threat Score
95/100

Date Published: 2026-05-13

Date Updated: 2026-05-22

Author: AnuPriya

...
...

A critical CVE-2026-43898 vulnerability in the @nyariv/sandboxjs npm package (≤ 0.9.5) allows attackers to escape the JavaScript sandbox and achieve full remote code execution by leaking an internal LispType.Call handler; the flaw has a CVSS score of 10.0, a working proof-of-concept was published, and a patched release (0.9.6) is available — users are urged to update immediately or stop executing untrusted scripts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.