logo

Critical 10.0 CVSS SandboxJS Flaw Grants Complete Remote Code Execution

ID: bde1f207-9e05-56c7-984d-c7c03c3cb9c2

STIX ID: report--bde1f207-9e05-56c7-984d-c7c03c3cb9c2

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-03-16

Date Updated: 2026-04-23

Author: Ddos

...
...

This advisory describes CVE-2026-26954, a critical (CVSS 10) vulnerability in SandboxJS that allows attackers to obtain the JavaScript Function constructor via manipulated object methods (for example, Object.entries(this).at(1) or Object.values(this).slice(1, 2)), enabling sandbox escape and remote code execution. All versions up to and including 0.8.33 are affected; maintainers released patch 0.8.34 and recommend immediate updates, dependency audits, and applying least-privilege principles for host processes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.