CVE-2026-23830: Critical SandboxJS Flaw (CVSS 10) Allows Total Sandbox Escape
ID: 7f3954d4-8871-567f-9429-0c2fadc3c7cc
STIX ID: report--7f3954d4-8871-567f-9429-0c2fadc3c7cc
Feed Name: securityonline.info
Threat Score
A critical sandbox-escape vulnerability (CVE-2026-23830) in SandboxJS allows an attacker to obtain native AsyncFunction/GeneratorFunction constructors from within the sandbox (e.g., via (async ()=>{}).constructor), enabling creation of functions that execute in the host global scope and achieve remote code execution; all versions prior to 0.8.26 are affected and maintainers released a fix in 0.8.26 to map and isolate the asynchronous function constructors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
