216.73.217.22

CVE-2026-43898

· Published 28/05/2026 18:16 · Modified 28/05/2026 20:16

Labels: CVE-2026-43898 2026-05-28CVE-2026-43898CWE-94[email protected]

Essential information

Published
28/05/2026 18:16
Modified
28/05/2026 20:16
Author
Creator
CVSS
10.0 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CVSS metrics

Description

SandboxJS is a JavaScript sandboxing library. Prior to 0.9.6, sandbox-defined functions expose Function.caller, allowing sandboxed code to recover the internal LispType.Call runtime callback. That callback can then be invoked with attacker-controlled fake context and obj values to extract blocked host statics, recover the real host Function constructor, and execute arbitrary host JavaScript. This vulnerability is fixed in 0.9.6.

NVD status

Status
Modified — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
nyariv / sandboxjs cpe:2.3:a:nyariv:sandboxjs:*:*:*:*:*:node.js:*:*

References