CVE-2023-26919

Severity CVSS v4.0:
Pending analysis
Type:
CWE-74 Injection
Publication date:
10/04/2023
Last modified:
11/02/2025

Description

delight-nashorn-sandbox 0.2.4 and 0.2.5 is vulnerable to sandbox escape. When allowExitFunctions is set to false, the loadWithNewGlobal function can be used to invoke the exit and quit methods to exit the Java process.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:javadelight:nashorn_sandbox:0.2.4:*:*:*:*:*:*:*
cpe:2.3:a:javadelight:nashorn_sandbox:0.2.5:*:*:*:*:*:*:*