CVE-2025-34146High· 7.0▾ MidnightPoC availableA prototype pollution vulnerability exists in @nyariv/sandboxjs versions <= 0.8.23, allowing attackers to inject arbitrary properties into Object.prototype via crafted JavaScript code. This can result in a denial-of-service (DoS) conditi…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 38.5 · likelihood 0 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake. The CVSS score shown above comes from the assigning CNA record, not NVD.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
A prototype pollution vulnerability exists in @nyariv/sandboxjs versions <= 0.8.23, allowing attackers to inject arbitrary properties into Object.prototype via crafted JavaScript code. This can result in a denial-of-service (DoS) condition or, under certain conditions, escape the sandboxed environment intended to restrict code execution. The vulnerability stems from insufficient prototype access checks in the sandbox’s executor logic, particularly in the handling of JavaScript function objects returned.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2011-10019Critical· 9.8Spreecommerce versions prior to 0.60.2 contains a remote command execution vulnerability in its search functionality
CVE-2026-105844Critical· 9.3Payload is a free and open source headless content management system
CVE-2026-104849Critical· 9.5Tinypool is a minimal Node.js worker thread pool implementation
CVE-2026-104848Critical· 9.5Tinypool is a minimal Node.js worker thread pool implementation
CVE-2026-104183Medium· 5.1stream-json is a micro-library of stream components for processing JSON and JSONC with a minimal memory footprint
CVE-2026-102992Critical· 9.2piscina is a node.js worker pool implementation