<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 12:54:23 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-05058</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-05058</link>
      <description>bdu:2026-05058</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-05058</guid>
    </item>
    <item>
      <title>EUVD-2026-267764</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-267764</link>
      <description>EUVD-2026-267764</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-267764</guid>
    </item>
    <item>
      <title>fkie_cve-2026-25881</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-25881</link>
      <description>&lt;p&gt;SandboxJS is a JavaScript sandboxing library. Prior to 0.8.31, a sandbox escape vulnerability allows sandboxed code to mutate host built-in prototypes by laundering the isGlobal protection flag through array literal intermediaries. When a global prototype reference (e.g., Map.prototype, Set.prototype) is placed into an array and retrieved, the isGlobal taint is stripped, permitting direct prototype mutation from within the sandbox. This results in persistent host-side prototype pollution and may enable RCE in applications that use polluted properties in sensitive sinks (example gadget: execSync(obj.cmd)). This vulnerability is fixed in 0.8.31.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;SandboxJS is a JavaScript sandboxing library. Prior to 0.8.31, a sandbox escape vulnerability allows sandboxed code to mutate host built-in prototypes by laundering the isGlobal protection flag through array literal intermediaries. When a global prototype reference (e.g., Map.prototype, Set.prototype) is placed into an array and retrieved, the isGlobal taint is stripped, permitting direct prototype mutation from within the sandbox. This results in persistent host-side prototype pollution and may enable RCE in applications that use polluted properties in sensitive sinks (example gadget: execSync(obj.cmd)). This vulnerability is fixed in 0.8.31.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-25881</guid>
    </item>
    <item>
      <title>GHSA-ww7g-4gwx-m7wj — @nyariv/sandboxjs has host prototype pollution from sandbox via array intermediary (sandbox escape)</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-ww7g-4gwx-m7wj</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @nyariv/sandboxjs&lt;/p&gt;
&lt;p&gt;### Summary
A sandbox escape vulnerability allows sandboxed code to mutate host built-in prototypes by laundering the `isGlobal` protection flag through array literal intermediaries. When a global prototype reference (e.g., `Map.prototype`, `Set.prototype`) is placed into an array and retrieved, the `isGlobal` taint is stripped, permitting direct prototype mutation from within the sandbox. This results in persistent host-side prototype pollution and may enable RCE in applications that use polluted properties in sensitive sinks (example gadget: `execSync(obj.cmd)`).&lt;/p&gt;
&lt;p&gt;### Details
#### Root Cause:
The sandbox implements a protection mechanism using the `isGlobal` flag in the Prop class to prevent modification of global objects and their prototypes. However, this taint tracking is lost when values pass through array/object literal creation.&lt;/p&gt;
&lt;p&gt;#### Vulnerable Code Path `src/executor.ts`([L559-L571](https://github.com/nyariv/SandboxJS/blob/main/src/executor.ts#L559-L571)):
```ts
addOps(LispType.CreateArray, (exec, done, ticks, a, b: Lisp[], obj, context, scope) =&amp;gt; {
  const items = (b as LispItem[])
    .map((item) =&amp;gt; {
      if (item instanceof SpreadArray) {
        return [...item.item];
      } else {
        return item;
      }
    })
    .flat()
    .map((item) =&amp;gt; valueOrProp(item, context));  // &amp;lt;- isGlobal flag lost here
  done(undefined, items);
});
```
#### Exploitation Flow:
```txt
Sandboxed code: const m=[Map.prototype][0]
              ↓
Array creation: isGlobal taint…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @nyariv/sandboxjs&lt;/p&gt;
&lt;p&gt;### Summary
A sandbox escape vulnerability allows sandboxed code to mutate host built-in prototypes by laundering the `isGlobal` protection flag through array literal intermediaries. When a global prototype reference (e.g., `Map.prototype`, `Set.prototype`) is placed into an array and retrieved, the `isGlobal` taint is stripped, permitting direct prototype mutation from within the sandbox. This results in persistent host-side prototype pollution and may enable RCE in applications that use polluted properties in sensitive sinks (example gadget: `execSync(obj.cmd)`).&lt;/p&gt;
&lt;p&gt;### Details
#### Root Cause:
The sandbox implements a protection mechanism using the `isGlobal` flag in the Prop class to prevent modification of global objects and their prototypes. However, this taint tracking is lost when values pass through array/object literal creation.&lt;/p&gt;
&lt;p&gt;#### Vulnerable Code Path `src/executor.ts`([L559-L571](https://github.com/nyariv/SandboxJS/blob/main/src/executor.ts#L559-L571)):
```ts
addOps(LispType.CreateArray, (exec, done, ticks, a, b: Lisp[], obj, context, scope) =&amp;gt; {
  const items = (b as LispItem[])
    .map((item) =&amp;gt; {
      if (item instanceof SpreadArray) {
        return [...item.item];
      } else {
        return item;
      }
    })
    .flat()
    .map((item) =&amp;gt; valueOrProp(item, context));  // &amp;lt;- isGlobal flag lost here
  done(undefined, items);
});
```
#### Exploitation Flow:
```txt
Sandboxed code: const m=[Map.prototype][0]
              ↓
Array creation: isGlobal taint…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-ww7g-4gwx-m7wj</guid>
    </item>
  </channel>
</rss>
