All intelligence
// vulnerability record
cached · NVD via COSMOS syncCVE-2026-25586
CRITICALpublished 2026-02-06 20:16 UTC · 6 months ago · modified 2026-06-17 10:24 UTC
10.0
CVSS / 10
// description
SandboxJS is a JavaScript sandboxing library. Prior to 0.8.29, a sandbox escape is possible by shadowing hasOwnProperty on a sandbox object, which disables prototype whitelist enforcement in the property-access path. This permits direct access to __proto__ and other blocked prototype properties, enabling host Object.prototype pollution and persistent cross-sandbox impact. This vulnerability is fixed in 0.8.29.
// weaknesses (CWE)
- CWE-74