logo

CVE-2026-34208 (CVSS 10): Critical Sandbox Escape Uncovered in SandboxJS

ID: 6f52074d-5fa5-583b-9f73-92d2bf558373

STIX ID: report--6f52074d-5fa5-583b-9f73-92d2bf558373

Feed Name: securityonline.info

Threat Score
92/100

Date Published: 2026-04-08

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical vulnerability (CVE-2026-34208) in SandboxJS permits guest code to access an exposed SandboxGlobal constructor (via this.constructor.call()) to perform arbitrary writes to host objects (such as Math or JSON), bypassing sandbox assignment checks; these mutations persist across the host runtime and new sandbox instances, enabling process-wide poisoning, potential supply-chain effects, and data exfiltration. The report assigns a CVSS score of 10.0 and recommends updating to the latest SandboxJS where the constructor is protected.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.