@nyariv/sandboxjs
13 known vulnerabilities · 1 critical · 2 high
@nyariv/sandboxjs vulnerable to sandbox escape via TOCTOU bug on keys in property accesses
SandboxJS Vulnerable to Prototype Pollution -> Sandbox Escape -> RCE
SandboxJS: Stack overflow DoS via deeply nested expressions in recursive descent parser
SandboxJS has an execution-quota bypass (cross-sandbox currentTicks race) in SandboxJS timers
@nyariv/sandboxjs has Prototype Pollution vulnerability that may lead to RCE
@nyariv/sandboxjs has host prototype pollution from sandbox via array intermediary (sandbox escape)
SandboxJS: Sandbox Escape via Prop Object Leak in New Handler
@nyariv/sandboxjs has Sandbox Escape via Prototype Whitelist Bypass and Host Prototype Pollution
SandboxJS has Sandbox Escape via Unprotected AsyncFunction Constructor