CVE-2026-23830 | nyariv SandboxJS up to 0.8.25 AsyncGenerator AsyncFunction code injection (GHSA-wxhw-j4hc-fmq6 / CNNVD-202601-4627)
A vulnerability, which was classified as critical, has been found in nyariv SandboxJS up to 0.8.25. The impacted element is the function AsyncFunction of the component AsyncGenerator Handler. This manipulation causes code injection.
This vulnerability is handled as CVE-2026-23830. The attack can be initiated remotely. There is not any exploit available.
It is advisable to upgrade the affected component.