CRITICAL: isolated-vm (<6.2.0, <7.0.1) Node.js lib flaw allows escaping V8 sandbox & RCE on host. Exploit: type confusion in ExternalCopy/TOCTOU. Patch to 6.2.0+ or 7.0.1+ now. https:// radar.offseq.c

js lib flaw allows escaping V8 sandbox & RCE on host. Exploit: type confusion in ExternalCopy/TOCTOU.

3 reportsother

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

CRITICAL: isolated-vm (<6.2.0, <7.0.1) Node.js lib flaw allows escaping V8 sandbox & RCE on host. Exploit: type confusion in ExternalCopy/TOCTOU. Patch to 6.2.0+ or 7.0.1+ now. https:// radar.offseq.c

mastodon:infosec-exchangeother39d ago kagi ↗

CRITICAL: isolated-vm (<6.2.0, <7.0.1) Node.js lib flaw allows escaping V8 sandbox & RCE on host. Exploit: type confusion in ExternalCopy/TOCTOU. Patch to 6.2.0+ or 7.0.1+ now. https:// radar.offseq.com/threat/critic al-isolated-vm-vulnerability-leads-to-rce-on-host-00e974a44c510748 # OffSeq # Nodejs # RCE # Vulnerability

Critical vulnerability in isolated-vm: a type confusion flaw in ExternalCopy's transferList mechanism allows memory corruption that breaks the guest/host sandbox boundary. Guest code can achieve RCE o

mastodon:infosec-exchangeother39d ago kagi ↗

Critical vulnerability in isolated-vm: a type confusion flaw in ExternalCopy's transferList mechanism allows memory corruption that breaks the guest/host sandbox boundary. Guest code can achieve RCE on the host process. Any deployment running untrusted JavaScript through this Node.js library is at risk. Patch immediately. # IsolatedVM # TypeConfusion # SandboxEscape # RCE https:// cyberworldops.eu

⚠️ PATCH NOW isolated-vm, the sandbox that runs untrusted JavaScript in ~1M projects a week, has a critical flaw: guest code can escape and run on the host. Self-host n8n-style AI automation? Update t

mastodon:infosec-exchangeother38d ago kagi ↗

⚠️ PATCH NOW isolated-vm, the sandbox that runs untrusted JavaScript in ~1M projects a week, has a critical flaw: guest code can escape and run on the host. Self-host n8n-style AI automation? Update to 7.0.1 or 6.2.0. https:// suriq.io/blog/isolated-vm-sand box-escape-host-rce # infosec # cybersecurity