Critical SandboxJS Flaw Enables Host System Takeover
ID: 11e508ab-b4aa-5d89-822e-4f0db17665a2
STIX ID: report--11e508ab-b4aa-5d89-822e-4f0db17665a2
Feed Name: Cyber Press
Threat Score
A critical CVE-2026-43898 vulnerability in the @nyariv/sandboxjs npm package (≤ 0.9.5) allows attackers to escape the JavaScript sandbox and achieve full remote code execution by leaking an internal LispType.Call handler; the flaw has a CVSS score of 10.0, a working proof-of-concept was published, and a patched release (0.9.6) is available — users are urged to update immediately or stop executing untrusted scripts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
