OVERVIEW CVE-2026-34208 affects SandboxJS, a JavaScript sandboxing library, in versions prior to 0.8.36. The vulnerability exploits a bypass in the library's protection mechanisms that are designed to prevent direct assignment to global objects. Attackers can circumvent these controls by leveraging an exposed callable constructor path (this.constructor.call), allowing arbitrary property injection into host global objects that persists across multiple sandbox instances within the same process. SEVERITY This vulnerability carries a CVSS 3.1 score of 10.0 CRITICAL with a network-based attack vector requiring no privileges or user interaction. The attack complexity is low, meaning exploitation is straightforward. The impact is severe, affecting confidentiality, integrity, and availability across scope boundaries, enabling attackers to read sensitive data, modify critical objects, and potentially disrupt sandbox isolation entirely. EXPLOITATION STATUS The vulnerability is not currently listed in the CISA KEV catalog and remains inactive on vulnerability hot lists. The EPSS score of 0.0018 indicates relatively low real-world exploitation probability compared to the broader CVE dataset. However, organizations running unpatched versions of SandboxJS prior to 0.8.36 should prioritize updates, as the simplicity of the exploitation technique and critical severity rating present significant risk despite limited current public exploitation activity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.8.36CPE matchmatch criteria | cpe:2.3:a:nyariv:sandboxjs:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.