< BACK TO NEWS
importantSYS.SOURCE: The Hacker News2026-08-20T19:18:24+05:30

Critical Isolated-vm Vulnerability Allows Sandboxed JavaScript to Escape to Host for RCE

A critical security flaw in the isolated-vm library allows sandboxed JavaScript to escape to the host process, enabling potential remote code execution (RCE). The vulnerability, patched in versions 6.2.0 and 7.0.1, exploits a type confusion in the ExternalCopy component to corrupt host memory and bypass isolation boundaries.

Cybersecurity researchers have disclosed a critical security flaw in isolated-vm, a popular open-source sandbox with more than 2,900 stars and 190 forks on GitHub, that could allow attackers to escape the confines of the isolated environment.

The vulnerability ("GHSA-864f-rcv7-6rh4"), which has yet to be assigned a CVE identifier, impacts all versions of the library before and including 7.0.0.

Read original article

*** END OF TRANSMISSION ***