Junglewise Threat Intelligence

CVE-2025-34146: nyariv SandboxJS prototype pollution and sandbox escape

CVE-2025-34146 · Severity: medium · CVSS 4 · Published 2025-07-31

Technologies: Nyariv Sandboxjs, @nyariv/sandboxjs (npm). Vendors: Nyariv, npm.

Executive brief

@nyariv/SandboxJS is a JavaScript sandbox library used to safely execute untrusted code. A prototype pollution vulnerability in versions 0.8.23 and earlier allows attackers to inject arbitrary properties into JavaScript's Object.prototype via crafted code, potentially breaking the sandbox's isolation and enabling denial-of-service attacks or code execution outside the intended restrictions.

Technical details

A prototype pollution vulnerability (CWE-1321) exists in @nyariv/SandboxJS versions ≤0.8.23, stemming from insufficient prototype access checks in the sandbox executor logic. Attackers can exploit this by crafting JavaScript code that chains prototype access (e.g., via String methods) to reach Object.prototype and inject arbitrary properties using __defineGetter__. The attack is local, requires no authentication or user interaction, and can be triggered by any code compiled and executed within the sandbox. Successful exploitation can result in denial-of-service conditions or, under certain conditions, escape the sandboxed environment entirely. The vulnerability was patched in version 0.8.24.

Affected products

  • nyariv SandboxJS ≤0.8.23

Timeline

  • 2025-04-12: disclosed: Issue opened on GitHub
  • 2025-07-31: advisory: GHSA-9qm3-6qrr-c76m published
  • 2025-07-31: patched: Fix released in version 0.8.24

References

Related threats