Vendor
Nyariv vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 12 vulnerabilities in Nyariv: 0 in the last 7 days and 0 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-43898, was published on 28 May 2026. 1 technology has a page of its own.
- Last 7 days
- 0
- Last 90 days
- 0
- Critical, all time
- 1
- Exploited in the wild
- 0
About Nyariv
nyariv is an open-source software developer on GitHub.
Nyariv technologies
Latest Nyariv vulnerabilities
- CVE-2026-43898: nyariv SandboxJS sandbox escape via Function.caller leakagecriticalCVSS 10EPSS 0.6%
- CVE-2026-34217: SandboxJS sandbox escape via Prop object leak in new handlermediumCVSS 4EPSS 0.4%
- CVE-2026-34211: SandboxJS stack overflow via deeply nested expressionsmediumCVSS 4EPSS 0.5%
- CVE-2026-34208: SandboxJS sandbox integrity escape via constructor manipulationlowCVSS 3.1EPSS 0.6%
- CVE-2026-32723: SandboxJS execution-quota bypass in timersmediumCVSS 4EPSS 0.1%
- CVE-2026-26954: SandboxJS sandbox escape allowing remote code executionlowCVSS 3.1EPSS 0.6%
- CVE-2026-25881: nyariv SandboxJS sandbox escape via prototype pollutionlowCVSS 3.1EPSS 0.6%
- CVE-2026-25586: nyariv sandboxjs sandbox escape via prototype whitelist bypasslowCVSS 3.1EPSS 0.7%
- CVE-2026-25520: nyariv sandboxjs sandbox escape to RCElowCVSS 3.1EPSS 0.8%
- CVE-2026-25142: SandboxJS prototype pollution vulnerability leading to sandbox escape and RCElowCVSS 3.1EPSS 1.1%
- CVE-2026-23830: SandboxJS sandbox escape via unprotected AsyncFunction constructorlowCVSS 3.1EPSS 1.3%
- CVE-2025-34146: nyariv SandboxJS prototype pollution and sandbox escapemediumCVSS 4EPSS 0.2%
Most severe Nyariv vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-43898: nyariv SandboxJS sandbox escape via Function.caller leakagecriticalCVSS 10EPSS 0.6%
- CVE-2026-34211: SandboxJS stack overflow via deeply nested expressionsmediumCVSS 4EPSS 0.5%
- CVE-2026-34217: SandboxJS sandbox escape via Prop object leak in new handlermediumCVSS 4EPSS 0.4%
- CVE-2025-34146: nyariv SandboxJS prototype pollution and sandbox escapemediumCVSS 4EPSS 0.2%
- CVE-2026-32723: SandboxJS execution-quota bypass in timersmediumCVSS 4EPSS 0.1%
- CVE-2026-23830: SandboxJS sandbox escape via unprotected AsyncFunction constructorlowCVSS 3.1EPSS 1.3%
- CVE-2026-25142: SandboxJS prototype pollution vulnerability leading to sandbox escape and RCElowCVSS 3.1EPSS 1.1%
- CVE-2026-25520: nyariv sandboxjs sandbox escape to RCElowCVSS 3.1EPSS 0.8%
- CVE-2026-25586: nyariv sandboxjs sandbox escape via prototype whitelist bypasslowCVSS 3.1EPSS 0.7%
- CVE-2026-25881: nyariv SandboxJS sandbox escape via prototype pollutionlowCVSS 3.1EPSS 0.6%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/nyariv.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Nyariv vulnerabilities", https://junglewise.ai/threats/vendors/nyariv, 26 September 2026.