A critical vulnerability in the Node.js sandboxing library isolated-vm allows guest JavaScript to escape its sandbox, corrupt host memory, and potentially achieve remote code execution. Tracked as GHSA-864f-rcv7-6rh4 and awaiting a CVE, the flaw was disclosed by Endor Labs as a type confusion bug in ExternalCopy handling of the transferList option. Researchers said the issue stems from a time-of-check/time-of-use gap across two iterations of a JavaScript array, where attacker-controlled getters can return an ArrayBuffer during validation and a different value during unchecked use, leading to unsafe behavior in the host process.
The bug affects all versions through 7.0.0, with fixes released in 6.2.0 and 7.0.1. Endor Labs demonstrated exploitation beginning with only a single ivm.Reference exposed to the sandbox, first triggering a controlled host crash and then hijacking host control flow to call a chosen libc function. The maintainer patched the issue by blocking JavaScript execution during the copy operation using v8::Isolate::DisallowJavascriptExecutionScope. The disclosure is especially significant because isolated-vm is widely used to run untrusted code despite longstanding project warnings that misuse of objects such as Reference and ExternalCopy, as well as unsafe handling of snapshots or cachedData, can undermine isolation and expose the main Node.js process.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
The isolated-vm maintainer fixed the vulnerability in versions 6.2.0 and 7.0.1 by wrapping ExternalCopy::Copy with v8::Isolate::DisallowJavascriptExecutionScope. The change prevents JavaScript execution during the copy operation, blocking the getter-based time-of-check/time-of-use exploit path.
Researchers showed exploitation starting with only a single ivm.Reference exposed to the sandbox, first triggering a controlled SIGSEGV crash and then escalating to host control-flow hijacking via attacker-controlled memory. They reported a path toward remote code execution while noting the V8 Isolate boundary itself was not broken.
Endor Labs disclosed a critical vulnerability in isolated-vm, tracked as GHSA-864f-rcv7-6rh4 and pending CVE assignment. The bug is a type confusion in ExternalCopy's transferList handling that can let sandboxed code corrupt host memory and escape to the host process.
The isolated-vm project documentation states that the library is in maintenance mode and warns that using it to run untrusted code is not inherently safe. The maintainer documents risks including process crashes, hangs, unsafe object exposure, and arbitrary code execution risks from snapshots or cachedData.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcesecurityweek.com
Open sourcethehackernews.com
Open sourceendorlabs.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.