Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE

Read full story on The Hacker News
Share
Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE
AI disclosure

Summary

Cybersecurity researchers have disclosed a critical security flaw in isolated-vm, a popular open-source sandbox with more than 2,900 stars and 190 forks on GitHub, that could allow attackers to escape the confines of the isolated environment. The vulnerability ("GHSA-864f-rcv7-6rh4"), which has yet to be assigned a CVE identifier, impacts all versions of the library before and including 7.0.0.

Original reporting

Open original source
Read full article on The Hacker News

Get the AFBytes Brief

Major stories, AI-assisted analysis, and what to watch next. Free, monthly, unsubscribe anytime.