Sandbox Breakout: Critical SandboxJS Flaw (CVE-2026-25881) Allows Host Takeover
ID: 6ccb3a61-23fe-5d45-a53b-f4965786ce93
STIX ID: report--6ccb3a61-23fe-5d45-a53b-f4965786ce93
Feed Name: securityonline.info
Threat Score
A critical sandbox escape vulnerability (CVE-2026-25881) in SandboxJS allows laundering of the library's isGlobal protection through array intermediaries, enabling prototype pollution from within the sandbox and potentially leading to remote code execution (example gadget: execSync(obj.cmd)). The issue affects versions prior to 0.8.31 and is fixed in 0.8.31; developers running untrusted JavaScript via SandboxJS are urged to upgrade immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
