CVE-2026-25520 | nyariv SandboxJS up to 0.8.28 hosts Object.values/Object.entries injection (GHSA-58jh-xv4v-pcx4 / EUVD-2026-5591)
A vulnerability classified as problematic was found in nyariv SandboxJS up to 0.8.28. The impacted element is the function hosts. The manipulation of the argument Object.values/Object.entries results in injection.
This vulnerability is identified as CVE-2026-25520. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is advised.