Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Fontainebleau forest near Paris reopens after devastating wildfire

    August 22, 2026

    Germany becomes Europe’s largest regulated cannabis market

    August 22, 2026

    Set Up a Separate Work Profile on Your Android Phone

    August 22, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Fontainebleau forest near Paris reopens after devastating wildfire
    • Germany becomes Europe’s largest regulated cannabis market
    • Set Up a Separate Work Profile on Your Android Phone
    • Hackers infect Android car head units with proxy botnet malware
    • AI Has Made Bitcoin Software a Target—This Group Is Fighting Back
    • Exercise may work better for keeping weight off than losing it
    • Low vaccination rates drive southwest Wisconsin measles outbreak
    • Israeli drone strike on ‘civilian vehicle’ injures several in Syria | Conflict News
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, August 22
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 22, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananAug 20, 2026Vulnerability / Application Security

    Cybersecurity researchers have disclosed a critical security flaw in isolated-vm, a popular open-source sandbox with more than 2,900 stars and 190 forks on GitHub, that could allow attackers to escape the confines of the isolated environment.

    The vulnerability (“GHSA-864f-rcv7-6rh4“), which has yet to be assigned a CVE identifier, impacts all versions of the library before and including 7.0.0. It has been patched in versions 6.2.0 and 7.0.1 released earlier this month.

    Isolated-vm is a Node.js library for running untrusted JavaScript inside a V8 Isolate, an independent instance of the Google V8 JavaScript engine, allowing multiple sandboxed JavaScript environments to run concurrently without sharing data or interfering with each other. The npm package has witnessed nearly 1 million downloads over the past week.

    Cybersecurity

    Because each V8 Isolate has a separate state and maintains its own heap, it is not possible to directly pass JavaScript objects from the main Node.js thread into a worker isolate. Isolated-vm exposes a class called ExternalCopy to securely serialize JavaScript objects out of the host isolate and deserialize them into the guest isolate.

    The vulnerability identified by Endor Labs resides in this component, allowing code running inside the sandbox to break out and corrupt memory in the host application.

    “A type confusion in ExternalCopy’s handling of the transferList option lets code running inside the sandbox corrupt memory in the host process,” Endor Labs researcher Cristian-Alexandru Staicu, who is credited with discovering and reporting the flaw, said in a technical write-up shared with The Hacker News.

    “Starting from nothing but a single ivm.Reference, the standard way hosts hand a sandbox any capability at all, we escalated the bug from a controlled-address crash all the way to hijacking the host’s control flow, demonstrating a full guest-to-host sandbox escape.”

    Successful exploitation of the flaw allows memory corruption in the host process, causing the host process to crash with a segmentation fault (SIGSEGV). It can also lead to a guest-to-host sandbox escape and an erosion of the trust boundary that undermines the very purpose of isolated-vm.

    “Minimum demonstrated impact is a reliable, controlled-address crash (denial-of-service) triggerable by any guest that has been given an ivm.Reference (the standard way to grant a sandbox any capability),” project maintainer Marcel Laverdet said in an advisory.

    Cybersecurity

    “Maximum demonstrated impact is control-flow hijack of the host process, i.e., potential remote code execution in the host.”

    Users who have isolated-vm installed in their developer environments are advised to update to the latest version for optimal protection. Additional details of the full exploit have been withheld so as to prevent bad actors from launching their own attacks.

    “The most important takeaway is that what was not broken was the isolation primitive itself,” Staicu said. “V8’s Isolate boundary held. What failed was the C++ glue code that marshals values across that boundary. A perfectly sound building block was undermined by the binding layer wrapped around it.”

    Escape Flaw Host Isolatedvm JavaScript lets potential RCE Sandboxed
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Hackers infect Android car head units with proxy botnet malware

    Microsoft Patches Severe Entra ID Flaw (CVSS 10.0) Allowing Remote Code Execution

    Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0

    CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities

    Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight

    Wazuh and AI For Enhanced SOC Workflows

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Fontainebleau forest near Paris reopens after devastating wildfire

    August 22, 2026

    Germany becomes Europe’s largest regulated cannabis market

    August 22, 2026

    Set Up a Separate Work Profile on Your Android Phone

    August 22, 2026

    Hackers infect Android car head units with proxy botnet malware

    August 22, 2026
    Latest Posts

    Satirical fake Guardian front page on ‘genetic links’ between eating bacon and far-right activism shared as genuine – Full Fact

    July 28, 2026

    U.S. Foreign Policy Must Prioritize Human Rights

    July 28, 2026

    Madison revisits police body cameras after years of debate

    July 28, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Fontainebleau forest near Paris reopens after devastating wildfire

    August 22, 2026

    Germany becomes Europe’s largest regulated cannabis market

    August 22, 2026

    Set Up a Separate Work Profile on Your Android Phone

    August 22, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.