isolated-vm, a popular open-source Node.js library for running untrusted JavaScript in V8 isolates, patched a critical vulnerability (GHSA-864f-rcv7-6rh4) in versions 6.2.0 and 7.0.1. The flaw allowed sandboxed code to corrupt host memory and potentially achieve remote code execution.