CVE-2026-26954: Sandboxjs Call Result Missing Sanitize Arraycve-2026-26954-sandboxjs-call-result-missing-sanitize-array
Native function call result is filtered only through getGlobalProp() and returned via done(...) without passing through sanitizeArray(). getGlobalProp() only inspects the top-level reference; arrays returned by native functions (e.g. Object.values, Array.at, Array.slice) can still contain raw global constructors such as Function, enabling sandbox escape (CVE