Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Nyariv

First CVE: Jul 31, 2025Active for: 1 yearTotal CVEs: 14
52.4
VTI Score
TOP TARGET

Nyariv maintains a focused vulnerability footprint centered on the SandboxJS product, a JavaScript sandbox implementation whose security-critical isolation role concentrates risk and severity in a narrow but prominent component. Its durable signal spans code-injection and prototype-pollution vulnerabilities alongside race conditions and broader injection weaknesses that reflect the parsing and execution-control demands of sandboxing untrusted code; the severity profile skews strongly toward critical outcomes. Defenders should treat SandboxJS updates as high-priority given the barrier-breaking nature of sandbox escapes; live severity and exploitation activity are shown alongside this summary.

FAUCET AI Generated
14
Total CVEs
More Total CVEs than 94% of tracked vendors
7.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 99% of tracked vendors
9.0
Avg CVSS Score
Higher Avg CVSS Score than 87% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Nyariv over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 31, 2025
11 months ago
Most Recent CVE
May 28, 2026
59 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-43898CRITICAL
SandboxJS is a JavaScript sandboxing library. Prior to 0.9.6, sandbox-defined functions expose Function.caller, allowing sandboxed code to recover the internal LispType.Call runtim
May 28, 202610.039NONO
CVE-2026-34208CRITICAL
SandboxJS is a JavaScript sandboxing library. Prior to 0.8.36, SandboxJS blocks direct assignment to global objects (for example Math.random = ...), but this protection can be bypa
Apr 6, 202610.035NONO
CVE-2026-26954CRITICAL
SandboxJS is a JavaScript sandboxing library. Prior to 0.8.34, it is possible to obtain arrays containing Function, which allows escaping the sandbox. Given an array containing Fun
Mar 13, 202610.034NONO
CVE-2026-23830CRITICAL
SandboxJS is a JavaScript sandboxing library. Versions prior to 0.8.26 have a sandbox escape vulnerability due to `AsyncFunction` not being isolated in `SandboxFunction`. The libra
Jan 28, 202610.034NONO
CVE-2026-25586CRITICAL
SandboxJS is a JavaScript sandboxing library. Prior to 0.8.29, a sandbox escape is possible by shadowing hasOwnProperty on a sandbox object, which disables prototype whitelist enfo
Feb 6, 202610.033NONO
CVE-2026-25520CRITICAL
SandboxJS is a JavaScript sandboxing library. Prior to 0.8.29, The return values of functions aren't wrapped. Object.values/Object.entries can be used to get an Array containing th
Feb 6, 202610.033NONO
CVE-2026-25142CRITICAL
SandboxJS is a JavaScript sandboxing library. Prior to 0.8.27, SanboxJS does not properly restrict __lookupGetter__ which can be used to obtain prototypes, which can be used for es
Feb 2, 202610.032NONO
CVE-2026-25881CRITICAL
SandboxJS is a JavaScript sandboxing library. Prior to 0.8.31, a sandbox escape vulnerability allows sandboxed code to mutate host built-in prototypes by laundering the isGlobal pr
Feb 9, 202610.030NONO
CVE-2026-25587CRITICAL
SandboxJS is a JavaScript sandboxing library. Prior to 0.8.29, as Map is in SAFE_PROTOYPES, it's prototype can be obtained via Map.prototype. By overwriting Map.prototype.has the s
Feb 6, 202610.028NONO
CVE-2026-25641CRITICAL
SandboxJS is a JavaScript sandboxing library. Prior to 0.8.29, there is a sandbox escape vulnerability due to a mismatch between the key on which the validation is performed and th
Feb 6, 20269.026NONO
View all 14 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products14 CVEs
21%
71%
Severity distribution among all CVEs352,719 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (14.3%)
Network12 (85.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (85.7%)
High2 (14.3%)
Unknown0 (0.0%)
User Interaction
None14 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low1 (7.1%)
High0 (0.0%)
None13 (92.9%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Nyariv.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Nyariv — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Nyariv's Products

View all 2 CNAs →

Top CWEs