


Perceptive Security
SOC/SIEM Consultancy

SandboxJS is a JavaScript sandboxing library. Prior to 0.9.6, sandbox-defined functions expose Function.caller, allowing sandboxed code to recover the internal …
Published:
27 mei 2026 om 22:00:00
Alert date:
28 mei 2026 om 21:01:38
Source:
nvd.nist.gov
Web Technologies, Supply Chain & Dependencies
SandboxJS JavaScript sandboxing library contains a critical sandbox escape vulnerability in versions prior to 0.9.6. The vulnerability allows sandboxed code to exploit Function.caller exposure in sandbox-defined functions to recover internal LispType.Call runtime callbacks. Attackers can invoke these callbacks with malicious context and object values to extract blocked host statics, recover the real host Function constructor, and execute arbitrary host JavaScript code, completely bypassing sandbox protections. This represents a complete sandbox escape that could lead to arbitrary code execution in the host environment. The vulnerability has been patched in version 0.9.6.
Technical details
Mitigation steps:
Affected products:
SandboxJS
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-43898
https://github.com/nyariv/SandboxJS/commit/826865251232611ec94078bab5a18ec875dad4a5
https://github.com/nyariv/SandboxJS/security/advisories/GHSA-g8f2-4f4f-5jqw
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
