Endor Labs, a cybersecurity company, identified a critical vulnerability in the isolated-vm Node.js library. The flaw, GHSA-864f-rcv7-6rh4, allows sandboxed code to escape and potentially achieve remote code execution on the host. Endor Labs researcher Cristian-Alexandru Staicu demonstrated the full exploit chain.