CRITICAL글로벌 · 취약점 · 2026년 8월 20일The Hacker News
isolated-vm 취약점으로 샌드박스 탈출 및 호스트 공격 가능
Cybersecurity researchers have discovered a critical security flaw in isolated-vm, a popular open-source sandbox for Node.js, allowing attackers to escape the sandbox and potentially execute code on the host system. The vulnerability, which has been patched in the latest versions, affects all prior versions of the library. The flaw resides in the ExternalCopy component, enabling code within the sandbox to corrupt memory in the host process, leading to a potential remote code execution. Users are advised to update to the latest version for protection.