logo

CVE-2026-23830: Critical SandboxJS Flaw (CVSS 10) Allows Total Sandbox Escape

ID: 7f3954d4-8871-567f-9429-0c2fadc3c7cc

STIX ID: report--7f3954d4-8871-567f-9429-0c2fadc3c7cc

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-01-29

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical sandbox-escape vulnerability (CVE-2026-23830) in SandboxJS allows an attacker to obtain native AsyncFunction/GeneratorFunction constructors from within the sandbox (e.g., via (async ()=>{}).constructor), enabling creation of functions that execute in the host global scope and achieve remote code execution; all versions prior to 0.8.26 are affected and maintainers released a fix in 0.8.26 to map and isolate the asynchronous function constructors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.