Isolated-vm Flaw Allows JavaScript Sandbox Escape to Host
A critical security flaw has been disclosed in ‘isolated-vm,’ a popular open-source JavaScript sandbox. This vulnerability, currently without a CVE, impacts all versions up to and including 7.0.0 and could allow attackers to escape the isolated environment to the host system. This poses a significant risk for applications relying on ‘isolated-vm’ for sandboxing untrusted code.