LIVE · cybersecurity feed
Live wire
javascriptcritical

Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE

A critical vulnerability has been discovered in the isolated-vm Node.js library, allowing sandboxed JavaScript code to escape and potentially execute arbitrary code on the host system. The flaw, found in the ExternalCopy component, enables memory corruption and control-flow hijacking. While the isolation primitive itself remains sound, the C++ binding layer that facilitates data transfer across boundaries was found to be vulnerable. Patches are available in versions 6.2.0 and 7.0.1.

zeroday.news ·

A significant security vulnerability has been identified in the isolated-vm Node.js library, which could allow sandboxed JavaScript code to escape its intended isolation and potentially achieve arbitrary code execution on the host system. The flaw specifically impacts the ExternalCopy component of the library.

The vulnerability stems from memory corruption issues within the ExternalCopy component, which is responsible for facilitating data transfer across the isolation boundaries. This corruption can lead to control-flow hijacking, effectively allowing malicious code to break out of the JavaScript sandbox. While the core isolation primitive provided by isolated-vm is reported to remain sound, the C++ binding layer that implements the data transfer mechanism was found to be susceptible to this issue.

The isolated-vm library is designed to execute untrusted JavaScript code in a secure, isolated environment, often used in applications that process user-supplied scripts or run third-party code. The ExternalCopy component's role is critical in allowing data to be safely exchanged between the isolated VM and the host Node.js process. A flaw in this component undermines the integrity of that exchange, creating an avenue for escape.

Successful exploitation of such a vulnerability typically involves crafting malicious JavaScript code that, when executed within the isolated-vm sandbox, triggers the memory corruption in the ExternalCopy component. This corruption can then be leveraged to manipulate program execution flow on the host, potentially leading to remote code execution (RCE) if the vulnerable application is exposed over a network.

For users of the isolated-vm library, immediate action is recommended. Patches addressing this vulnerability have been released and are available in versions 6.2.0 and 7.0.1 of the library. Developers are advised to update their dependencies to these or newer versions to mitigate the risk of exploitation.

This class of vulnerability, often involving a sandbox escape, highlights the persistent challenges in securing complex software environments that integrate multiple languages or execution contexts. While sandboxing is a fundamental security control, the interfaces and binding layers between sandboxed and host environments frequently present attack surfaces that require rigorous scrutiny and robust error handling to prevent memory corruption and control-flow hijacking.

javascriptsandbox escapenode.jsvulnerabilityrce
ShareXLinkedInWhatsAppFacebook

More News

view all →
security

Calling on Cyber Pros to Help Defend City Hall

Government agencies with smaller budgets need support — and here's how you can help.

security

Who Got Missed in the MFA Rollout? More Powershell + Graph + Entra scripting!, (Fri, Aug 21st)

In every MFA rollout, there will come a time where you think you are closing in on "done", and some automation to list what&#;x26;#;39;s left would be handy. Something quicker than scrolling through the web interface through thousands of accounts ... This is that method. Also, remember when we discussed yesterday about the beta graph commands in the Microsoft.Graph.Beta library? We&#;x26;#;39;ll u

security

Even MOAR Powershell, looking at Entra logins - the good, the bad and the password sprays, (Fri, Aug 21st)

One thing that folks never seem to do after "going to the CLOOOOUUUUD" is to look at their logs, logs that they would have checked daily when things were on premise. One log that really bears looking at is the log of successful and failed logins. the call for that is:

phishing

Russian snoops add OAuth abuse to targeted phishing campaigns

Don't click on that State Department meeting invite

security

China Is Strapping ‘Digital Bombs’ to Civilian Infrastructure—Is the US Ready?

This week on “Uncanny Valley,” Andy Greenberg discusses sitting in on a war game simulating a cyberattack from the Chinese hacking group Volt Typhoon

nation-state

Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts

Three distinct suspected Russian cyber espionage threat clusters have been observed leveraging legitimate authentication flows to single out individuals working in academia, aerospace and defense, governments, and think tanks across Europe, as well as academia and think tanks within the U.S. These clusters include UNC6293, UNC7005, and UNC5976. "These clusters engage in persistent, adaptive