Critical isolated-vm Flaw Lets Untrusted JavaScript Escape Sandbox and Hijack Host Execution

A critical security flaw in the popular Node.js sandboxing library isolated-vm could allow untrusted JavaScript to escape its V8 sandbox and potentially hijack execution in the host process. The issue, tracked as GHSA-864f-rcv7-6rh4 and awaiting a CVE identifier, affects isolated-vm versions earlier than 7.0.1 and 6.2.0. The maintainers released fixes on August 8, 2026. The […]

This article has been indexed from Cyber Security News

Read the original article: