Nyariv maintains a focused vulnerability footprint centered on the SandboxJS product, a JavaScript sandbox implementation whose security-critical isolation role concentrates risk and severity in a narrow but prominent component. Its durable signal spans code-injection and prototype-pollution vulnerabilities alongside race conditions and broader injection weaknesses that reflect the parsing and execution-control demands of sandboxing untrusted code; the severity profile skews strongly toward critical outcomes. Defenders should treat SandboxJS updates as high-priority given the barrier-breaking nature of sandbox escapes; live severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nyariv over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-43898CRITICAL SandboxJS is a JavaScript sandboxing library. Prior to 0.9.6, sandbox-defined functions expose Function.caller, allowing sandboxed code to recover the internal LispType.Call runtim | May 28, 2026 | 10.0 | 39 | NO | NO |
CVE-2026-34208CRITICAL SandboxJS is a JavaScript sandboxing library. Prior to 0.8.36, SandboxJS blocks direct assignment to global objects (for example Math.random = ...), but this protection can be bypa | Apr 6, 2026 | 10.0 | 35 | NO | NO |
CVE-2026-26954CRITICAL SandboxJS is a JavaScript sandboxing library. Prior to 0.8.34, it is possible to obtain arrays containing Function, which allows escaping the sandbox. Given an array containing Fun | Mar 13, 2026 | 10.0 | 34 | NO | NO |
CVE-2026-23830CRITICAL SandboxJS is a JavaScript sandboxing library. Versions prior to 0.8.26 have a sandbox escape vulnerability due to `AsyncFunction` not being isolated in `SandboxFunction`. The libra | Jan 28, 2026 | 10.0 | 34 | NO | NO |
CVE-2026-25586CRITICAL SandboxJS is a JavaScript sandboxing library. Prior to 0.8.29, a sandbox escape is possible by shadowing hasOwnProperty on a sandbox object, which disables prototype whitelist enfo | Feb 6, 2026 | 10.0 | 33 | NO | NO |
CVE-2026-25520CRITICAL SandboxJS is a JavaScript sandboxing library. Prior to 0.8.29, The return values of functions aren't wrapped. Object.values/Object.entries can be used to get an Array containing th | Feb 6, 2026 | 10.0 | 33 | NO | NO |
CVE-2026-25142CRITICAL SandboxJS is a JavaScript sandboxing library. Prior to 0.8.27, SanboxJS does not properly restrict __lookupGetter__ which can be used to obtain prototypes, which can be used for es | Feb 2, 2026 | 10.0 | 32 | NO | NO |
CVE-2026-25881CRITICAL SandboxJS is a JavaScript sandboxing library. Prior to 0.8.31, a sandbox escape vulnerability allows sandboxed code to mutate host built-in prototypes by laundering the isGlobal pr | Feb 9, 2026 | 10.0 | 30 | NO | NO |
CVE-2026-25587CRITICAL SandboxJS is a JavaScript sandboxing library. Prior to 0.8.29, as Map is in SAFE_PROTOYPES, it's prototype can be obtained via Map.prototype. By overwriting Map.prototype.has the s | Feb 6, 2026 | 10.0 | 28 | NO | NO |
CVE-2026-25641CRITICAL SandboxJS is a JavaScript sandboxing library. Prior to 0.8.29, there is a sandbox escape vulnerability due to a mismatch between the key on which the validation is performed and th | Feb 6, 2026 | 9.0 | 26 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nyariv.
Media articles that mention a CVE ID that affects a product developed by Nyariv — matched by CVE ID, not by vendor name.