logo

Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE

ID: 989bfd23-5034-537d-8e8b-40a0fd58ddea

STIX ID: report--989bfd23-5034-537d-8e8b-40a0fd58ddea

Feed Name: The Hacker News

Threat Score
65/100

Date Published: 2026-08-20

Date Updated: 2026-08-20

Author: [email protected] (The Hacker News)

...
...

Security researchers disclosed a critical type-confusion vulnerability in the isolated-vm Node.js sandbox library that allows code running inside a guest V8 isolate to corrupt host memory and potentially hijack host control flow, effectively enabling a sandbox escape and possible remote code execution. The flaw affects versions up to 7.0.0, has been patched in 6.2.0 and 7.0.1, and maintainers recommend updating; no active exploitation in the wild is reported in the document.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.