← Back to browse · API

CVE-2026-25142

Severity
CRITICAL
CVSS
10.0
EPSS
0.01091
Risk score
40.38
CISA KEV
No
PoC
No
Published
2026-02-02
Modified
2026-02-04
First seen
2026-08-07
Aliases
EUVD-2026-5407, GHSA-9P4W-FQ8M-2HP7
Products
nyariv:sandboxjs < 0.8.27
Sources
euvd EUVD-2026-5407

Description

SandboxJS is a JavaScript sandboxing library. Prior to 0.8.27, SanboxJS does not properly restrict __lookupGetter__ which can be used to obtain prototypes, which can be used for escaping the sandbox / remote code execution. This vulnerability is fixed in 0.8.27.

References