📦

sandboxjs

Vendor: nyariv

Actively Exploited 0 CISA KEV List
PoC / Exploits 1 Code Available
Total RCEs 6 Remote Access
Total CVEs 26 Total Indexed
Avg. EPSS 0.59% Exploit Prob.
Latest CVE CVE-2026-43898 May 28

Security Vulnerability Index

Page 1 / 3
10.0 CVSS

SandboxJS is a JavaScript sandboxing library. Prior to 0.9.6, sandbox-defined functions expose Function.caller, allowing sandboxed code to recover the internal LispType.Call runtime callback. That callback can then be invoked with attacker-controlled fake context and obj values to extract blocked host statics, recover the real host Function constructor, and execute arbitrary host JavaScript. This vulnerability is fixed in 0.9.6.

EPSS: 0.47%