top of page
perceptive_background_267k.jpg

SandboxJS is a JavaScript sandboxing library. Prior to 0.9.6, sandbox-defined functions expose Function.caller, allowing sandboxed code to recover the internal …

Published:

27 May 2026 at 22:00:00

Alert date:

28 May 2026 at 19:09:38

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Supply Chain & Dependencies

SandboxJS JavaScript sandboxing library contains a vulnerability in versions prior to 0.9.6 where sandbox-defined functions expose Function.caller, allowing sandboxed code to recover internal runtime callbacks. Attackers can exploit this to invoke callbacks with fake context and object values to extract blocked host statics, recover the real host Function constructor, and execute arbitrary host JavaScript code. This represents a complete sandbox escape vulnerability that allows malicious code to break out of the intended security boundaries. The vulnerability is fixed in version 0.9.6.

Technical details

Mitigation steps:

Affected products:

SandboxJS

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page