{"id":"CVE-2026-34217","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-34217","summary":"SandboxJS is a JavaScript sandboxing library. Prior to 0.8.36, a scope modification vulnerability exists in @nyariv/sandboxjs. The vulnerability allows untrusted sandboxed code to leak…","details":"SandboxJS is a JavaScript sandboxing library. Prior to 0.8.36, a scope modification vulnerability exists in @nyariv/sandboxjs. The vulnerability allows untrusted sandboxed code to leak internal interpreter objects through the new operator, exposing sandbox scope objects in the scope hierarchy to untrusted code; an unexpected and undesired exploit. While this could allow modifying scopes inside the sandbox, code evaluation remains sandboxed and prototypes remain protected throughout the execution. This vulnerability is fixed in 0.8.36.","published":"2026-04-06T16:16:34.890","modified":"2026-06-17T10:38:40.310","cvss":{"score":7.2,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[],"fix":null,"references":[{"type":"EXPLOIT","url":"https://github.com/nyariv/SandboxJS/security/advisories/GHSA-hg73-4w7g-q96w"},{"type":"EXPLOIT","url":"https://github.com/nyariv/SandboxJS/security/advisories/GHSA-hg73-4w7g-q96w"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-06-17T10:38:40.310"}}