Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE
Cybersecurity researchers have disclosed a critical security flaw in isolated-vm, a popular open-source sandbox with more than 2,900 stars and 190 forks on GitHub, that could allow attackers to escape the confines of the isolated environment. The vulnerability ("GHSA-864f-rcv7-6rh4"), which has yet to be assigned a CVE identifier, impacts all versions of the library before and including 7.0.0.
What happened
Cybersecurity researchers have disclosed a critical security flaw in isolated-vm, a popular open-source sandbox with more than 2,900 stars and 190 forks on GitHub, that could allow attackers to escape the confines of the isolated environment. The vulnerability ("GHSA-864f-rcv7-6rh4"), which has yet to be assigned a CVE identifier, impacts all versions of the library before and including 7.0.0.
Why it matters
The incident may affect operational continuity, asset safety or trust around Security. Watch for verified scope and remediation.
Affected entities
View evidence
1 reports · 1 original report · 1 independent
- The Hacker NewsPrimary source · Supports · EN · 100%Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE ↗
Claims
- Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE Observed
Conflicts
No material conflict detected in the available evidence.
Timeline
- First reported
- Unverified · 46/64%
Market move following event
Market reaction is not yet available for this asset and time window.