pkg:npm/@nyariv/sandboxjs
14 total CVEsCRITICAL10
✅ Check your installed version
All known vulnerabilities
- CRITICAL10.0CVE-2026-43898SandboxJS has a sandbox escape via Function.caller leakage of internal call opfrom 0, < 0.9.6
- from 0, < 0.8.36
- from 0, < 0.8.34
- CRITICAL10.0CVE-2026-25641@nyariv/sandboxjs vulnerable to sandbox escape via TOCTOU bug on keys in property accessesfrom 0, < 0.8.29
- from 0, < 0.8.29
- CRITICAL10.0CVE-2026-25586@nyariv/sandboxjs has Sandbox Escape via Prototype Whitelist Bypass and Host Prototype Pollutionfrom 0, < 0.8.29
- from 0, < 0.8.29
- from 0, < 0.8.27
- from 0, < 0.8.26
- CRITICAL9.0CVE-2026-25881@nyariv/sandboxjs has host prototype pollution from sandbox via array intermediary (sandbox escape)from 0, < 0.8.31
- from 0, < 0.8.36
- —CVE-2026-34211SandboxJS: Stack overflow DoS via deeply nested expressions in recursive descent parserfrom 0, < 0.8.36
- —CVE-2026-32723SandboxJS has an execution-quota bypass (cross-sandbox currentTicks race) in SandboxJS timersfrom 0, < 0.8.35
- from 0, < 0.8.24