Vulnerability Database

321,822

Total vulnerabilities in the database

CVE-2026-25142

SandboxJS is a JavaScript sandboxing library. Prior to 0.8.27, SanboxJS does not properly restrict lookupGetter which can be used to obtain prototypes, which can be used for escaping the sandbox / remote code execution. This vulnerability is fixed in 0.8.27.

  • Published: Feb 2, 2026
  • Updated: Feb 4, 2026
  • CVE: CVE-2026-25142
  • Severity: Critical
  • Exploit:

CVSS v3:

  • Severity: Critical
  • Score: 10
  • AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CWEs: