Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
SandboxJS Vulnerability Risks Host Security Breach

SandboxJS Vulnerability Risks Host Security Breach

Posted on May 13, 2026 By CWS

A significant security flaw has been discovered in SandboxJS, a popular JavaScript sandboxing library available on npm. This vulnerability allows malicious actors to escape the sandbox environment and execute arbitrary code on the host system.

Critical Security Threat

Identified as CVE-2026-43898, the flaw carries a critical severity score of 10.0, indicating the highest level of threat. This underscores the seriousness of the issue in today’s heightened cybersecurity environment.

All versions of the @nyariv/sandboxjs package, up to and including 0.9.5, are impacted. The core issue lies in the unintended leakage of a powerful internal callback, known as LispType.Call, from the sandbox-defined functions.

Once an attacker gains access to this callback, they can extend their reach beyond the sandbox, gaining full control over the host system.

Discovery and Proof of Concept

Security experts at GitHub were responsible for identifying this vulnerability, publishing an advisory under the identifier GHSA-g8f2-4f4f-5jqw. The discovery was made by a researcher known as Macabely, who also developed a proof-of-concept to demonstrate the potential real-world impact of this exploit.

The risk is substantial, as exploiting this flaw allows an attacker to achieve remote code execution on the host without requiring login credentials or user interaction. Applications utilizing this library to run untrusted JavaScript are at high risk of being compromised.

Mechanism of the Exploit

A corrected version, 0.9.6, has been released and is now available on npm. Users of the affected package are strongly urged to update immediately, as remaining on versions 0.9.5 and below leaves systems vulnerable to attack.

The vulnerability resides in the property access logic within a file named prop.ts, specifically in the addOps function. Sandboxed code could access the caller, callee, and arguments properties of functions, posing a security risk.

In the CommonJS build of the library, this flaw enabled sandboxed functions to call functions like function f(){ return f.caller }, exposing the internal callback. This callback, the LispType.Call, handles function calls within the runtime without verifying the origin of the parameters.

An attacker, controlling these fields, can manipulate the input to mislead the handler into executing unintended actions, ultimately gaining access to the host’s Function constructor. This allows them to execute arbitrary JavaScript code directly on the host.

Wider Implications and Precautions

The vulnerability’s CVSS score of 10.0 highlights its potential danger. The exploit can be executed over a network with low complexity, requiring no special privileges or user actions.

Any platform using SandboxJS for user-submitted or third-party JavaScript runs the risk of attack. This includes online code editors, server-side scripts, automation tools, and any application processing untrusted scripts.

Breaking the sandbox allows attackers to control the host’s confidentiality, integrity, and availability. The patch in version 0.9.6 addresses the root cause by blocking access to sensitive properties within sandboxed code.

Developers unable to update immediately should refrain from running untrusted JavaScript until the patch is applied and tested in their environments.

Cyber Security News Tags:addOps, CVE-2026-43898, Cybersecurity, GitHub, host takeover, JavaScript, LispType.Call, NPM, prop.ts, remote code execution, SandboxJS, security flaw, update patch, version 0.9.6, Vulnerability

Post navigation

Previous Post: 716,000 Affected by OpenLoop Health Cyber Breach
Next Post: Understanding and Mitigating Lethal Paths in AppSec

Related Posts

First AI Ransomware ‘PromptLock’ Uses OpenAI gpt-oss-20b Model for Encryption First AI Ransomware ‘PromptLock’ Uses OpenAI gpt-oss-20b Model for Encryption Cyber Security News
Hundreds of Thousands of Users Grok Chats Exposed in Google Search Results Hundreds of Thousands of Users Grok Chats Exposed in Google Search Results Cyber Security News
McDonald’s AI Hiring Bot With Password ‘123456’ Leaks Millions of Job-Seekers Data McDonald’s AI Hiring Bot With Password ‘123456’ Leaks Millions of Job-Seekers Data Cyber Security News
Water Saci Hackers Leveraging AI Tools to Attack WhatsApp Web Users Water Saci Hackers Leveraging AI Tools to Attack WhatsApp Web Users Cyber Security News
Hackers are Moving to “Living Off the Land” Techniques to Attack Windows Systems Bypassing EDR Hackers are Moving to “Living Off the Land” Techniques to Attack Windows Systems Bypassing EDR Cyber Security News
Cybercriminals Exploit Fake Avast Site for Credit Card Data Cybercriminals Exploit Fake Avast Site for Credit Card Data Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Russian Intelligence Phishing Campaign Targets Messaging Apps
  • Chinese Framework Fuels Massive Scam Network
  • OpenAI Unveils GPT-5.6 Sol with Enhanced Security
  • Critical Cloud Bucket Hijacking Threat Exposed
  • Claude Mythos 5 Redeployed to Protect US Infrastructure

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Russian Intelligence Phishing Campaign Targets Messaging Apps
  • Chinese Framework Fuels Massive Scam Network
  • OpenAI Unveils GPT-5.6 Sol with Enhanced Security
  • Critical Cloud Bucket Hijacking Threat Exposed
  • Claude Mythos 5 Redeployed to Protect US Infrastructure

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark