logo

Code Red: 4 Critical SandboxJS Flaws (CVSS 10.0) Allow Host Takeover

ID: 3629d04e-205e-5d76-93cc-8e8aa11c0a7f

STIX ID: report--3629d04e-205e-5d76-93cc-8e8aa11c0a7f

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-02-09

Date Updated: 2026-04-23

Author: Ddos

...
...

A quartet of critical vulnerabilities in SandboxJS (all CVSS 10.0) allow attackers to break out of the JavaScript sandbox and execute arbitrary code on the host by abusing unwrapped function return values, overwriting Map.prototype.has, shadowing hasOwnProperty to bypass whitelist checks, and exploiting a TOCTOU property key validation bug; maintainers patched the issues in v0.8.29, and affected versions are 0.8.28 and earlier.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.