August 21, 2026
4212151-0-39700400-1787259675-alexander-dummer-x4jRmkuDImo-unsplash.jpg

I show You how To Make Huge Profits In A Short Time With Cryptos!

A important sandbox escape vulnerability was found and patched in isolated-vm, a library for operating JavaScript code inside an remoted course of. If exploited, the vulnerability may permit attackers to hijack the host’s management stream, which may allow distant code execution.

Remoted-vm is downloaded greater than 1 million occasions per week and can be used as a direct or non-compulsory element in different tasks, together with open-source AI agent automation frameworks akin to n8n, Sim.ai, Mastra, and Activepieces. Its objective is to execute untrusted user-provided JavaScript code inside a sandbox created with the Isolate function in V8, the JavaScript engine from Chrome and Node.js.

“Operating untrusted JavaScript safely is without doubt one of the hardest issues within the Node.js ecosystem, and its historical past is plagued by failures,” mentioned Cris Staicu, lead researcher at appsec agency Edor Labs, who discovered the vulnerability. “Vm2, for years the default reply, accrued greater than twenty documented breakouts earlier than being deprecated.”



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *