Security: nyariv/SandboxJS
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
Sandbox escape via TOCTOU between property access checks and method callsGHSA-6hwh-3fp5-2m4f published
Aug 22, 2026 by nyarivCritical -
Sandbox escape via assignment to __proto__ in scope variable recordsGHSA-w2c7-wq77-2wj7 published
Aug 22, 2026 by nyarivCritical -
Sandbox escape to remote code execution in default new Sandbox() (scope __proto__ pollution + Error.prepareStackTrace op-callback leak + unsanitized Call-op function read)GHSA-x8hf-3qx4-x5qc published
Aug 22, 2026 by nyarivCritical -
Sandbox integrity bypass via generic Array mutator receiver abuseGHSA-xqh4-f3rm-rv9f published
Aug 22, 2026 by nyarivModerate -
Sandbox escape via Function.caller leakage of internal call opGHSA-g8f2-4f4f-5jqw published
May 9, 2026 by nyarivCritical -
Prop Object Leak in New HandlerGHSA-hg73-4w7g-q96w published
Apr 3, 2026 by nyarivModerate -
Stack overflow DoS via deeply nested expressions in recursive descent parserGHSA-8pfc-jjgw-6g26 published
Apr 3, 2026 by nyarivLow -
Sandbox integrity escapeGHSA-2gg9-6p7w-6cpj published
Apr 3, 2026 by nyarivCritical -
Execution-quota bypass (cross-sandbox currentTicks race) in SandboxJS timersGHSA-7p5m-xrh7-769r published
Mar 14, 2026 by nyarivModerate -
Sandbox EscapeGHSA-6r9f-759j-hjgv published
Mar 13, 2026 by nyarivCritical
Learn more about advisories related to nyariv/SandboxJS in the GitHub Advisory Database