VYPR
Critical severity10.0OSV Advisory· Published Feb 2, 2026· Updated Jun 17, 2026

CVE-2026-25142

CVE-2026-25142

Description

SandboxJS is a JavaScript sandboxing library. Prior to 0.8.27, SanboxJS does not properly restrict __lookupGetter__ which can be used to obtain prototypes, which can be used for escaping the sandbox / remote code execution. This vulnerability is fixed in 0.8.27.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
@nyariv/sandboxjsnpm
< 0.8.270.8.27

Affected products

3
  • Nyariv/SandboxjsOSV2 versions
    0.5.0, 0.5.2, 0.5.3, …+ 1 more
    • (no CPE)range: 0.5.0, 0.5.2, 0.5.3, …
    • cpe:2.3:a:nyariv:sandboxjs:*:*:*:*:*:node.js:*:*range: <0.8.27
  • ghsa-coords
    Range: < 0.8.27

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.