Junglewise Threat Intelligence

CVE-2026-34208: SandboxJS sandbox integrity escape via constructor manipulation

CVE-2026-34208 · Severity: low · CVSS 3.1 · Published 2026-04-03

Technologies: Nyariv Sandboxjs, @nyariv/sandboxjs (npm). Vendors: Nyariv, npm.

Executive brief

SandboxJS is a Node.js library that safely executes untrusted code in an isolated sandbox environment. The vulnerability allows malicious code to bypass sandbox protections and modify shared global objects (like Math or JSON) that persist across all sandbox instances in the same process. This could allow attackers to corrupt application behavior, steal data, or achieve code execution if the host application relies on the integrity of built-in functions.

Technical details

SandboxJS attempts to prevent untrusted code from modifying global objects by checking the isGlobal flag during assignment operations. However, the vulnerability exploits a privilege gap: the SandboxGlobal constructor function, which performs property writes via an internal loop, is callable from sandbox code via Function.prototype.call and is not subject to the same global-mutation restrictions. An attacker can invoke this constructor via this.constructor.call(target, payloadObject) to write arbitrary properties into any host global object (e.g., Math.random or JSON.stringify). Because these mutations occur at runtime in the shared process context, they persist across all subsequent sandbox instances and are visible to host code, enabling cross-instance contamination. The attack requires no authentication or user interaction and can be chained with host gadgets (application code that uses the mutated globals) to achieve broader compromise including potential code execution. Patches are available in version 0.8.36 and later.

Affected products

  • nyariv @nyariv/sandboxjs 0.8.35 and earlier

Timeline

  • 2026-04-03: disclosed: Advisory published
  • 2026-04-03: patched: Patched in version 0.8.36
  • 2026-04-06: other: NVD published CVE-2026-34208

References

Related threats