CVE-2026-25587 | nyariv SandboxJS up to 0.8.28 Map.prototype.has code injection (GHSA-66h4-qj4x-38xp / EUVD-2026-5590)
A vulnerability classified as critical has been found in nyariv SandboxJS up to 0.8.28. The affected element is the function Map.prototype.has. The manipulation leads to code injection.
This vulnerability is referenced as CVE-2026-25587. Remote exploitation of the attack is possible. No exploit is available.
It is recommended to upgrade the affected component.