Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-34208

35
FAUCET Score

OVERVIEW CVE-2026-34208 affects SandboxJS, a JavaScript sandboxing library, in versions prior to 0.8.36. The vulnerability exploits a bypass in the library's protection mechanisms that are designed to prevent direct assignment to global objects. Attackers can circumvent these controls by leveraging an exposed callable constructor path (this.constructor.call), allowing arbitrary property injection into host global objects that persists across multiple sandbox instances within the same process. SEVERITY This vulnerability carries a CVSS 3.1 score of 10.0 CRITICAL with a network-based attack vector requiring no privileges or user interaction. The attack complexity is low, meaning exploitation is straightforward. The impact is severe, affecting confidentiality, integrity, and availability across scope boundaries, enabling attackers to read sensitive data, modify critical objects, and potentially disrupt sandbox isolation entirely. EXPLOITATION STATUS The vulnerability is not currently listed in the CISA KEV catalog and remains inactive on vulnerability hot lists. The EPSS score of 0.0018 indicates relatively low real-world exploitation probability compared to the broader CVE dataset. However, organizations running unpatched versions of SandboxJS prior to 0.8.36 should prioritize updates, as the simplicity of the exploitation technique and critical severity rating present significant risk despite limited current public exploitation activity.

Impacted Technologies

VendorProductVersion(s)CPE
< 0.8.36CPE matchmatch criteria
cpe:2.3:a:nyariv:sandboxjs:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 3.1

10.0CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
LOW
Exploitability Score
3.9
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.56%
Probability of exploitation in next 30 days
EPSS Percentile
43.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0056 is in the 23rd percentile among its peer group of 36,835 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

npmpatch availablevia ghsa
Product: @nyariv/sandboxjsFixed in: 0.8.36
github_advisoryvendor investigatingvia nvd_reference
View patch

Vendor Advisories (1)

npmGHSA-2gg9-6p7w-6cpjcritical

SandboxJS: Sandbox integrity escape

Apr 3, 2026

References

github.com / nyariv/SandboxJS/security/advisories/GHSA-2gg9-6p7w-6cpj
ExploitVendor Advisory