CyberSecurityBoardThreat Intel · CVEs · Products
Cyber Products

isolated-vm Sandbox Library Patches Critical Escape Flaw

August 20, 2026

isolated-vm, a popular open-source Node.js library for running untrusted JavaScript in V8 isolates, patched a critical vulnerability (GHSA-864f-rcv7-6rh4) in versions 6.2.0 and 7.0.1. The flaw allowed sandboxed code to corrupt host memory and potentially achieve remote code execution.