Description

SandboxJS is a JavaScript sandboxing library. Prior to 0.8.36, a scope modification vulnerability exists in @nyariv/sandboxjs. The vulnerability allows untrusted sandboxed code to leak internal interpreter objects through the new operator, exposing sandbox scope objects in the scope hierarchy to untrusted code; an unexpected and undesired exploit. While this could allow modifying scopes inside the sandbox, code evaluation remains sandboxed and prototypes remain protected throughout the execution. This vulnerability is fixed in 0.8.36.

INFO

Published Date :

2026-04-06T15:12:52.871Z

Last Modified :

2026-04-06T15:40:46.653Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2026-34217 vulnerability.

Vendors Products
Nyariv
  • Sandboxjs
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2026-34217.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability