{"id":"CVE-2026-32723","aliases":["GHSA-7p5m-xrh7-769r"],"url":"https://o3.security/vulnerability/CVE-2026-32723","summary":"SandboxJS timers have an execution-quota bypass (cross-sandbox currentTicks race)","details":"SandboxJS is a JavaScript sandboxing library. Prior to 0.8.35, SandboxJS timers have an execution-quota bypass. A global tick state (`currentTicks.current`) is shared between sandboxes. Timer string handlers are compiled at execution time using that global tick state rather than the scheduling sandbox's tick object. In multi-tenant / concurrent sandbox scenarios, another sandbox can overwrite `currentTicks.current` between scheduling and execution, causing the timer callback to run under a different sandbox's tick budget and bypass the original sandbox's execution quota/watchdog. Version 0.8.35 fixes this issue.","published":"2026-03-18T21:27:35.349Z","modified":"2026-08-12T03:51:13.186278266Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@nyariv/sandboxjs","fixedVersion":"0.8.35"}],"fix":{"url":"https://github.com/nyariv/SandboxJS/commit/cc8f20b4928afed5478d5ad3d1737ef2dcfaac29","label":"nyariv/SandboxJS@cc8f20b"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/32xxx/CVE-2026-32723.json"},{"type":"ADVISORY","url":"https://github.com/nyariv/SandboxJS/security/advisories/GHSA-7p5m-xrh7-769r"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-32723"},{"type":"FIX","url":"https://github.com/nyariv/SandboxJS/commit/cc8f20b4928afed5478d5ad3d1737ef2dcfaac29"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:13.186278266Z"}}