PT-2026-6658 · Sandboxjs · Sandboxjs
Cristianstaicu
·
Published
2026-02-05
·
Updated
2026-02-09
·
CVE-2026-25641
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SandboxJS versions prior to 0.8.29
Description
SandboxJS, a JavaScript sandboxing library, has a sandbox escape issue. This is due to a mismatch between the key used for validation and the key used for property access. The key, intended to be a string, is not enforced as such, allowing attackers to use malicious objects that change string values during sanitization and property access. This could lead to remote code execution if an attacker can execute code within the sandbox.
Recommendations
Versions prior to 0.8.29 should be updated to version 0.8.29.
Exploit
Fix
Time Of Check To Time Of Use
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sandboxjs