logo

Sandbox Breakout: Critical SandboxJS Flaw (CVE-2026-25881) Allows Host Takeover

ID: 6ccb3a61-23fe-5d45-a53b-f4965786ce93

STIX ID: report--6ccb3a61-23fe-5d45-a53b-f4965786ce93

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-02-11

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical sandbox escape vulnerability (CVE-2026-25881) in SandboxJS allows laundering of the library's isGlobal protection through array intermediaries, enabling prototype pollution from within the sandbox and potentially leading to remote code execution (example gadget: execSync(obj.cmd)). The issue affects versions prior to 0.8.31 and is fixed in 0.8.31; developers running untrusted JavaScript via SandboxJS are urged to upgrade immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.