Critical Sandbox Escape in isolated-vm Allows Host Control-Flow Hijacking
A critical type confusion vulnerability in the isolated-vm library allows untrusted JavaScript to escape its sandbox and hijack the host process. The flaw enables remote code execution by exploiting a double-walk mechanism in the data transfer layer.
**If you run isolated-vm, directly or through platforms like n8n, Rocket.Chat, Directus, Budibase, Activepieces, Mastra AI, or Sim.ai update it to version 7.0.1 or 6.2.0 ASAP. Untrusted code can currently break out of the sandbox and take over your server. After updating, review your code and cut down how many objects you share with untrusted scripts. Treat any server that ran untrusted code before the patch as possibly compromised.**
#cybersecurity #infosec #advisory #vulnerabilityhttps://beyondmachines.net/event_details/critical-sandbox-escape-in-isolated-vm-allows-host-control-flow-hijacking-a-w-3-x-7/gD2P6Ple2L