CVE Watchtower


← Back to CVE List

CVE-2026-25587NVD

Description

SandboxJS is a JavaScript sandboxing library. Prior to 0.8.29, as Map is in SAFE_PROTOYPES, it's prototype can be obtained via Map.prototype. By overwriting Map.prototype.has the sandbox can be escaped. This vulnerability is fixed in 0.8.29.
Severity Level
CRITICAL (10.0)
Published Date
06/02/2026
Last Modified
18/02/2026
Exploitation Status
????