CVE-2026-26954: Sandboxjs Call Result Missing Sanitize Array

Native function call result is filtered only through getGlobalProp() and returned via done(...) without passing through sanitizeArray(). getGlobalProp() only inspects the top-level reference; arrays returned by native functions (e.g. Object.values, Array.at, Array.slice) can still contain raw global constructors such as Function, enabling sandbox escape (CVE

Provally CuratedPublic repositoryHighHigh confidenceVerifiedApache-2.0TS
greprules fetch cve-2026-26954-sandboxjs-call-result-missing-sanitize-array --engine opengrep

Description

Native function call result is filtered only through getGlobalProp() and returned via done(...) without passing through sanitizeArray(). getGlobalProp() only inspects the top-level reference; arrays returned by native functions (e.g. Object.values, Array.at, Array.slice) can still contain raw global constructors such as Function, enabling sandbox escape (CVE