As cited
Copy frozen at (site build).
vulnerabilities
Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE
Researchers disclosed a critical vulnerability in isolated-vm, a widely-used open-source JavaScript sandbox library, that enables attackers to escape the sandboxed environment and potentially achieve remote code execution on the host system. The flaw affects all versions through 7.0.0 and has been assigned a GitHub Security Advisory identifier pending CVE assignment.
Why it matters: Developers and organizations using isolated-vm in production environments to run untrusted JavaScript code face immediate risk of sandbox escape and host compromise; patching to a version after 7.0.0 is required to mitigate this exposure.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE
Researchers disclosed a critical vulnerability in isolated-vm, a widely-used open-source JavaScript sandbox library, that enables attackers to escape the sandboxed environment and potentially achieve remote code execution on the host system. The flaw affects all versions through 7.0.0 and has been assigned a GitHub Security Advisory identifier pending CVE assignment.
Why it matters: Developers and organizations using isolated-vm in production environments to run untrusted JavaScript code face immediate risk of sandbox escape and host compromise; patching to a version after 7.0.0 is required to mitigate this exposure.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE
Researchers disclosed a critical vulnerability in isolated-vm, a widely-used open-source JavaScript sandbox library, that enables attackers to escape the sandboxed environment and potentially achieve remote code execution on the host system. The flaw affects all versions through 7.0.0 and has been assigned a GitHub Security Advisory identifier pending CVE assignment.
Why it matters: Developers and organizations using isolated-vm in production environments to run untrusted JavaScript code face immediate risk of sandbox escape and host compromise; patching to a version after 7.0.0 is required to mitigate this exposure.
- Source published
- First seen by Cybersecurity Tracker