logo

CVSS 10 Alert: SandboxJS Critical Escape Vulnerability Enables Host Takeover

ID: f6665997-e2e6-5d4b-a229-53326bee310e

STIX ID: report--f6665997-e2e6-5d4b-a229-53326bee310e

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-05-13

Date Updated: 2026-05-13

Author: Ddos

...
...

A critical sandbox escape vulnerability (CVE-2026-43898, CVSS 10) was disclosed in the SandboxJS JavaScript sandboxing library; by exploiting Function.caller leakage when createFunction() generates host functions, sandboxed code can recover internal callbacks and achieve full remote code execution on the host. Users are urged to update to SandboxJS version 0.9.6 to remediate the issue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.