JavaScript Sandboxing Library Vulnerability in SandboxJS by Nyariv
CVE-2026-34208

10CRITICAL

Key Information:

Vendor

Nyariv

Status
Vendor
CVE Published:
6 April 2026

What is CVE-2026-34208?

SandboxJS, a JavaScript sandboxing library, has a significant vulnerability that enables attackers to bypass protections against direct assignment to global objects. Prior to version 0.8.36, an exposed callable constructor path allowed malicious code to use 'this.constructor.call(target, attackerObject)' to mutate host global objects. This compromise facilitates arbitrary property writes that persist across different sandbox instances within the same process, posing serious security implications for applications utilizing this library. The issue was resolved in version 0.8.36.

Affected Version(s)

SandboxJS < 0.8.36

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.