Vendorsnyarivsandboxjsany version
Vulnerabilities

nyariv SandboxJS any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

13CVEs
CVE-2026-23830
SandboxJS has Sandbox Escape via Unprotected AsyncFunction Constructor
Published 2026-01-27 · Analyzed
10.0EPSS 0.012
CVE-2026-25142
SandboxJS Prototype Pollution -> Sandbox Escape -> RCE
Published 2026-02-02 · Analyzed
10.0EPSS 0.011
CVE-2026-25520
SandboxJS has a Sandbox Escape
Published 2026-02-06 · Analyzed
10.0EPSS 0.008
CVE-2026-25586
SandboxJS has a Sandbox Escape via Prototype Whitelist Bypass and Host Prototype Pollution
Published 2026-02-06 · Analyzed
10.0EPSS 0.007
CVE-2026-25587
SandboxJS has a Sandbox Escape
Published 2026-02-06 · Analyzed
10.0EPSS 0.007
CVE-2026-25881
@nyariv/sandboxjs has host prototype pollution from sandbox via array intermediary (sandbox escape)
Published 2026-02-09 · Analyzed
10.0EPSS 0.006
CVE-2026-43898
SandboxJS: Sandbox escape via Function.caller leakage of internal call op
Published 2026-05-28 · Modified
10.0EPSS 0.006
CVE-2026-34208
SandboxJS: Sandbox integrity escape
Published 2026-04-06 · Analyzed
10.0EPSS 0.006
CVE-2026-26954
SandboxJS has a Sandbox Escape
Published 2026-03-13 · Analyzed
10.0EPSS 0.006
CVE-2026-25641
SandboxJS has a sandbox escape via TOCTOU bug on keys in property accesses
Published 2026-02-06 · Analyzed
10.0EPSS 0.005
CVE-2026-34211
SandboxJS: Stack overflow DoS via deeply nested expressions in recursive descent parser
Published 2026-04-06 · Analyzed
7.5EPSS 0.005
CVE-2026-34217
SandboxJS has a Sandbox Escape via Prop Object Leak in New Handler
Published 2026-04-06 · Analyzed
7.2EPSS 0.003
CVE-2026-32723
SandboxJS timers have an execution-quota bypass (cross-sandbox currentTicks race)
Published 2026-03-18 · Analyzed
4.8EPSS 0.001