Critical Flaw Found in Popular JavaScript Sandbox Tool 'isolated-vm'
Security researchers have disclosed a critical vulnerability in isolated-vm, a popular open-source sandboxing library used to safely run untrusted JavaScript code. The tool, which has attracted more than 2,900 stars and 190 forks on GitHub, is designed to keep potentially malicious code contained within an isolated environment, separate from the main application.
The flaw, tracked as GHSA-864f-rcv7-6rh4, has not yet been assigned an official CVE identifier but affects all versions of isolated-vm up to and including 7.0.0. If exploited, the vulnerability could allow attackers to escape the sandboxed environment entirely, potentially leading to remote code execution on the host system—undermining the very security protections the tool was built to provide.
Businesses that develop web applications or use third-party services relying on JavaScript sandboxing to process untrusted code should be aware that this library may be embedded in tools they use, even if not directly. Since many software products depend on layers of open-source components, a vulnerability like this can have a wide ripple effect across the software supply chain.