Количество 3
Количество 3
CVE-2026-26954
SandboxJS is a JavaScript sandboxing library. Prior to 0.8.34, it is possible to obtain arrays containing Function, which allows escaping the sandbox. Given an array containing Function, and Object.fromEntries, it is possible to construct {[p]: Function} where p is any constructible property. This vulnerability is fixed in 0.8.34.
GHSA-6r9f-759j-hjgv
SandboxJS affected by a Sandbox Escape
BDU:2026-04459
Уязвимость библиотеки SandboxJS, связанная с неверным управлением генерацией кода, позволяющая нарушителю выйти из изолированной программной среды
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-26954 SandboxJS is a JavaScript sandboxing library. Prior to 0.8.34, it is possible to obtain arrays containing Function, which allows escaping the sandbox. Given an array containing Function, and Object.fromEntries, it is possible to construct {[p]: Function} where p is any constructible property. This vulnerability is fixed in 0.8.34. | CVSS3: 10 | 1% Низкий | 5 месяцев назад | |
GHSA-6r9f-759j-hjgv SandboxJS affected by a Sandbox Escape | CVSS3: 10 | 1% Низкий | 5 месяцев назад | |
BDU:2026-04459 Уязвимость библиотеки SandboxJS, связанная с неверным управлением генерацией кода, позволяющая нарушителю выйти из изолированной программной среды | CVSS3: 10 | 1% Низкий | 5 месяцев назад |
Уязвимостей на страницу