CVE-2026-23830
Last modified
CVE-2026-23830 is a critical-severity vulnerability rated 10/10 on the CVSS scale. SandboxJS is a JavaScript sandboxing library. Versions prior to 0.8.26 have a sandbox escape vulnerability due to `AsyncFunction` not being isolated in `SandboxFunction`. EPSS estimates a 1.12% chance of exploitation in the next 30 days.
Description
SandboxJS is a JavaScript sandboxing library. Versions prior to 0.8.26 have a sandbox escape vulnerability due to `AsyncFunction` not being isolated in `SandboxFunction`. The library attempts to sandbox code execution by replacing the global `Function` constructor with a safe, sandboxed version (`SandboxFunction`). This is handled in `utils.ts` by mapping `Function` to `sandboxFunction` within a map used for lookups. However, before version 0.8.26, the library did not include mappings for `AsyncFunction`, `GeneratorFunction`, and `AsyncGeneratorFunction`. These constructors are not global properties but can be accessed via the `.constructor` property of an instance (e.g., `(async () => {}).constructor`). In `executor.ts`, property access is handled. When code running inside the sandbox accesses `.constructor` on an async function (which the sandbox allows creating), the `executor` retrieves the property value. Since `AsyncFunction` was not in the safe-replacement map, the `executor` returns the actual native host `AsyncFunction` constructor. Constructors for functions in JavaScript (like `Function`, `AsyncFunction`) create functions that execute in the global scope. By obtaining the host `AsyncFunction` constructor, an attacker can create a new async function that executes entirely outside the sandbox context, bypassing all restrictions and gaining full access to the host environment (Remote Code Execution). Version 0.8.26 patches this vulnerability.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Nyariv | Sandboxjs | < 0.8.26 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-23830?
How severe is CVE-2026-23830?
How do I fix CVE-2026-23830?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-23824Vulnerabilities exist in a protocol-handling component of AO…7.5
- CVE-2026-23825Vulnerabilities exist in a protocol-handling component of AO…7.5
- CVE-2026-23826A vulnerability in a network management service of AOS-8 Ope…7.5
- CVE-2026-23827A heap-based buffer overflow vulnerability exists in a Netwo…7.5
- CVE-2026-23829Mailpit is an email testing tool and API for developers. Pri…5.3
- CVE-2026-2383The Simple Download Monitor plugin for WordPress is vulnerab…6.4
- CVE-2026-23831Rekor is a software supply chain transparency log. In versio…5.3
- CVE-2026-23833ESPHome is a system to control microcontrollers remotely thr…7.5
- CVE-2026-23835LobeHub is an open source human-and-AI-agent network. Prior …5.7
- CVE-2026-23836HotCRP is conference review software. A problem introduced i…8.8
- CVE-2026-23837MyTube is a self-hosted downloader and player for several vi…9.8
- CVE-2026-23838Tandoor Recipes is a recipe manager than can be installed wi…8.7
Are you affected by CVE-2026-23830?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
