CyberSecurityBoardThreat Intel · CVEs · Products
Cyber Companies

Endor Labs Discovers Critical isolated-vm Sandbox Escape

June 25, 2026

Endor Labs, a cybersecurity company, identified a critical vulnerability in the isolated-vm Node.js library. The flaw, GHSA-864f-rcv7-6rh4, allows sandboxed code to escape and potentially achieve remote code execution on the host. Endor Labs researcher Cristian-Alexandru Staicu demonstrated the full exploit chain.