CVE 7 HIGH

nyariv sandboxjs 0.8.23 Prototype Pollution Sandbox Escape DoS_CVE-2025-34146

7 / 10
HIGH
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N

Description

A prototype pollution vulnerability exists in @nyariv/sandboxjs versions <= 0.8.23, allowing attackers to inject arbitrary properties into Object.prototype via crafted JavaScript code. This can result in a denial-of-service (DoS) condition or, under certain conditions, escape the sandboxed environment intended to restrict code execution. The vulnerability stems from insufficient prototype access checks in the sandbox’s executor logic, particularly in the handling of JavaScript function objects returned.

Basic Information

ID CVE-2025-34146
Source VulnCheck
Published Jul 31, 2025 at 14:59
Modified Jul 31, 2025 at 20:06

Affected Product

Vendor nyariv
Product sandboxjs
Version *
Affected Versions nyariv sandboxjs *

CWE Classification

References

πŸ’­ Join the Security Discussion

πŸ”’ Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.