Executive brief
SandboxJS is a JavaScript sandbox library used to safely execute untrusted code in isolated environments with configurable resource limits. A race condition in timer handling allows attackers to bypass execution quotas by manipulating shared global state, enabling CPU-intensive loops to run unchecked and exhaust system resources affecting the host and other tenants.
Technical details
The vulnerability is a race condition (CWE-362) in SandboxJS's timer implementation where a global tick state (currentTicks.current) shared across all sandbox instances is read at timer execution time rather than scheduling time. Timer string handlers are compiled lazily when the timer fires, allowing another sandbox running concurrently to overwrite currentTicks.current between scheduling and execution. This causes the timer callback to execute under a different sandbox's tick budget, bypassing the original sandbox's execution quota watchdog. Attack requires multiple concurrent sandbox instances in the same process; no authentication or network access needed. A malicious script can trigger CPU exhaustion or resource starvation attacks. The vulnerability was fixed in version 0.8.35.
Affected products
- nyariv SandboxJS <=0.8.34
Timeline
- 2026-03-16: disclosed
- 2026-03-16: patched: Fixed in version 0.8.35