isolated-vm Patches Critical Sandbox Escape Threatening AI Agents
isolated-vm is an open-source Node.js library that runs untrusted JavaScript inside separate V8 Isolates, making it a common building block for AI agents and automated workflows that execute generated or user-supplied code. The flaw matters because a sandbox is meant to contain failures and malicious behavior. If that boundary collapses, an attacker may move from controlling one task to compromising the host process and potentially the wider service.
Security advisory GHSA-864f-rcv7-6rh4 says type confusion in ExternalCopy’s handling of transferList allows code inside the sandbox to corrupt host memory and hijack control flow. Versions through 7.0.0 are affected. Maintainers released 7.0.1 and 6.2.0 on August 5, 2026, providing patched upgrade paths for the current major lines. Operators should update according to their Node.js compatibility requirements and rebuild deployment artifacts that bundle the native module.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →