{
  "id": 2467029,
  "title": "JavaScript Sandbox Escape via Type Confusion in isolated-vm",
  "url": "https://urgent.news/2026/08/22/javascript-sandbox-escape-via-type-confusion-in-isolated-vm",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-22T01:18:28.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/anoymask/javascript-sandbox-escape-via-type-confusion-in-isolated-vm-4op9"
  },
  "original_language": "en",
  "account": "The isolated-vm JavaScript sandbox contains a critical type confusion vulnerability, which allows untrusted code to escape the sandbox and take control of the host Node.js process. If exploited, this vulnerability could lead to arbitrary code execution with host privileges, potentially granting attackers access to sensitive data and credentials. The vulnerability exists in versions of isolated-vm lower than 7.0.1 and 6.2.0. It is triggered when untrusted code reaches the ExternalCopy constructor and an attacker-controlled value is returned by a getter during a transferList read. This results in control address manipulation and hijacking of the host control flow. Affected platforms include Node.js, V8, n8n, Activepieces, and Mastra AI. The vulnerability requires no user interaction, as it can be exploited through inputs to AI workflows or code execution features. Administrators and SOCs should monitor for abnormal crashes and memory access, as well as abnormal traffic patterns after exploitation. The high severity of this vulnerability warrants immediate updates to the affected versions or disabling of the vulnerable feature.",
  "summary": "1. Basic Information Article Name : GHSA-864f-rcv7-6rh4: Critical Type Confusion Vulnerability in isolated-vm Publisher : Endor Labs Publication Date : 2026-08-20 Update Date : None Severity : high Original Source : https://www.endorlabs.com/learn/ghsa-864f-rcv7-6rh4-critical-type-confusion-vulnerability-in-isolated-vm Related Sources : GHSA-864f-rcv7-6rh4 , Critical isolated-vm vulnerability…",
  "key_points": [
    "Critical type confusion vulnerability in isolated-vm JavaScript sandbox",
    "Untrusted code can escape sandbox, gain host process control",
    "Exploits affect Node.js, V8, n8n, Activepieces, Mastra AI"
  ],
  "editors_take": "This vulnerability forces immediate updates or feature disabling for users of isolated-vm, particularly on platforms like Node.js and n8n, to prevent potential code execution with host privileges and data breaches.",
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}