<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 02:45:25 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-280493</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-280493</link>
      <description>EUVD-2026-280493</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-280493</guid>
    </item>
    <item>
      <title>fkie_cve-2026-34208</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-34208</link>
      <description>&lt;p&gt;SandboxJS is a JavaScript sandboxing library. Prior to 0.8.36, SandboxJS blocks direct assignment to global objects (for example Math.random = ...), but this protection can be bypassed through an exposed callable constructor path: this.constructor.call(target, attackerObject). Because this.constructor resolves to the internal SandboxGlobal function and Function.prototype.call is allowed, attacker code can write arbitrary properties into host global objects and persist those mutations across sandbox instances in the same process. This vulnerability is fixed in 0.8.36.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;SandboxJS is a JavaScript sandboxing library. Prior to 0.8.36, SandboxJS blocks direct assignment to global objects (for example Math.random = ...), but this protection can be bypassed through an exposed callable constructor path: this.constructor.call(target, attackerObject). Because this.constructor resolves to the internal SandboxGlobal function and Function.prototype.call is allowed, attacker code can write arbitrary properties into host global objects and persist those mutations across sandbox instances in the same process. This vulnerability is fixed in 0.8.36.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-34208</guid>
    </item>
    <item>
      <title>GHSA-2gg9-6p7w-6cpj — SandboxJS: Sandbox integrity escape</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-2gg9-6p7w-6cpj</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @nyariv/sandboxjs&lt;/p&gt;
&lt;p&gt;### Summary
SandboxJS blocks direct assignment to global objects (for example `Math.random = ...`), but this protection can be bypassed through an exposed callable constructor path: `this.constructor.call(target, attackerObject)`. Because `this.constructor` resolves to the internal `SandboxGlobal` function and `Function.prototype.call` is allowed, attacker code can write arbitrary properties into host global objects and persist those mutations across sandbox instances in the same process.&lt;/p&gt;
&lt;p&gt;### Details
The intended safety model relies on write-time checks in assignment operations. In `assignCheck`, writes are denied when the destination is marked global (`obj.isGlobal`), which correctly blocks straightforward payloads like `Math.random = () =&amp;gt; 1`.&lt;/p&gt;
&lt;p&gt;Reference: [`src/executor.ts#L215-L218`](https://github.com/nyariv/SandboxJS/blob/cc8f20b4928afed5478d5ad3d1737ef2dcfaac29/src/executor.ts#L215-L218)&lt;/p&gt;
&lt;p&gt;```ts
if (obj.isGlobal) {
  throw new SandboxAccessError(
    `Cannot ${op} property &amp;#39;${obj.prop.toString()}&amp;#39; of a global object`,
  );
}
```&lt;/p&gt;
&lt;p&gt;The bypass works because the dangerous write is not performed by an assignment opcode. Instead, attacker code reaches a host callable that performs writes internally. The constructor used for sandbox global objects is `SandboxGlobal`, implemented as a function that copies all keys from a provided object into `this`.&lt;/p&gt;
&lt;p&gt;Reference: [`src/utils.ts#L84-L88`](https://github.com/nyariv/SandboxJS/blob/cc8f20b4928afed5478d5ad3d1737ef2dcfaac29/src/utils.…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @nyariv/sandboxjs&lt;/p&gt;
&lt;p&gt;### Summary
SandboxJS blocks direct assignment to global objects (for example `Math.random = ...`), but this protection can be bypassed through an exposed callable constructor path: `this.constructor.call(target, attackerObject)`. Because `this.constructor` resolves to the internal `SandboxGlobal` function and `Function.prototype.call` is allowed, attacker code can write arbitrary properties into host global objects and persist those mutations across sandbox instances in the same process.&lt;/p&gt;
&lt;p&gt;### Details
The intended safety model relies on write-time checks in assignment operations. In `assignCheck`, writes are denied when the destination is marked global (`obj.isGlobal`), which correctly blocks straightforward payloads like `Math.random = () =&amp;gt; 1`.&lt;/p&gt;
&lt;p&gt;Reference: [`src/executor.ts#L215-L218`](https://github.com/nyariv/SandboxJS/blob/cc8f20b4928afed5478d5ad3d1737ef2dcfaac29/src/executor.ts#L215-L218)&lt;/p&gt;
&lt;p&gt;```ts
if (obj.isGlobal) {
  throw new SandboxAccessError(
    `Cannot ${op} property &amp;#39;${obj.prop.toString()}&amp;#39; of a global object`,
  );
}
```&lt;/p&gt;
&lt;p&gt;The bypass works because the dangerous write is not performed by an assignment opcode. Instead, attacker code reaches a host callable that performs writes internally. The constructor used for sandbox global objects is `SandboxGlobal`, implemented as a function that copies all keys from a provided object into `this`.&lt;/p&gt;
&lt;p&gt;Reference: [`src/utils.ts#L84-L88`](https://github.com/nyariv/SandboxJS/blob/cc8f20b4928afed5478d5ad3d1737ef2dcfaac29/src/utils.…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-2gg9-6p7w-6cpj</guid>
    </item>
  </channel>
</rss>
