CYBER CODE RED

Get real-time updates on Telegram

P5Verified

CVE-2025-34146: sandboxjs 0 through 0.8.23

CVE-2025-34146. EPSS 0.00211 (percentile 0.10452), scored 2026-10-06.

Affected technology

sandboxjs · 0 through 0.8.23
nyariv

Description’s affected range: versions <= 0.8.23

Component: dist/node/executor.js, dist/node/parser.js
Function: objects

Attack conditions (Vendor/CNA, CVSS 4.0): Local · No privileges required · No user interaction required

What an attacker can do

The source reports that an attacker could disrupt service. Vendor/CNA’s CVSS 4.0 assessment (base score 7.0/10) rates confidentiality impact as none; integrity and availability impact as high.

Published

CWE
CWE-1321
CCR priority
0.1 /100 (P5)
EPSS
0.00211 · percentile 0.105 · 2026-10-08
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2025-34146.html