JavaScript Sandboxing Library Vulnerability in SandboxJS by Nyariv
CVE-2026-34208
10CRITICAL
What is CVE-2026-34208?
SandboxJS, a JavaScript sandboxing library, has a significant vulnerability that enables attackers to bypass protections against direct assignment to global objects. Prior to version 0.8.36, an exposed callable constructor path allowed malicious code to use 'this.constructor.call(target, attackerObject)' to mutate host global objects. This compromise facilitates arbitrary property writes that persist across different sandbox instances within the same process, posing serious security implications for applications utilizing this library. The issue was resolved in version 0.8.36.
Affected Version(s)
SandboxJS < 0.8.36
