CuraSec

Plan active

isolated-vm Sandbox Escape Flaw Enables Host RCE in All Versions ≤7.0.0

2026-08-21 11:38 UTC · The Hacker News · read the source ↗ #sandbox-escape#javascript#rce
  • Engineer — Plan: Any Node.js service using isolated-vm to run untrusted code (plugins, user-submitted scripts, multi-tenant eval) is exposed to host RCE; no public PoC or KEV listing yet, but the impact ceiling is high — audit your dependency tree and upgrade isolated-vm to a version above 7.0.0 this sprint.
  • SOC/IR — Skip
  • Leader — Skip
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.