news.mlab.sh
Back to the feed
vulnerability

Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE

Critical
Image: The Hacker News
Summary

A critical vulnerability in isolated-vm, a popular JavaScript sandbox library, allows attackers to escape the sandbox environment and potentially execute code on the host system. The flaw stems from a type confusion issue within the ExternalCopy component, leading to memory corruption and potential remote code execution. Users are advised to update to version 6.2.0 or 7.0.1 to mitigate the risk.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.