PT-2026-6658 · Sandboxjs · Sandboxjs

Cristianstaicu

·

Published

2026-02-05

·

Updated

2026-02-09

·

CVE-2026-25641

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SandboxJS versions prior to 0.8.29
Description SandboxJS, a JavaScript sandboxing library, has a sandbox escape issue. This is due to a mismatch between the key used for validation and the key used for property access. The key, intended to be a string, is not enforced as such, allowing attackers to use malicious objects that change string values during sanitization and property access. This could lead to remote code execution if an attacker can execute code within the sandbox.
Recommendations Versions prior to 0.8.29 should be updated to version 0.8.29.

Exploit

Fix

Time Of Check To Time Of Use

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2026-25641
GHSA-7X3H-RM86-3342

Affected Products

Sandboxjs