Live
Enforcing US Data Residency with Cloudflare D1AI agents CI: why repository‑centric pipelines are breakingAI Agent Inbox: Deploy Pizza Bot for Background Task ExecutionOpenAPPA delivers zero‑success prompt‑injection protection in benchmark tests – what AI engineers need to knowEU Cyber Resilience Act expands software supply‑chain responsibilities for digital product manufacturersTyped Probability Model Jev Shifts AI Output from Text to Structured DecisionsBasin Pipelines per‑stream ingest capacity jumps to 1 GB/s – what engineers need to knowAI‑driven vulnerability management: moving from CVE counts to contextual riskEnforcing US Data Residency with Cloudflare D1AI agents CI: why repository‑centric pipelines are breakingAI Agent Inbox: Deploy Pizza Bot for Background Task ExecutionOpenAPPA delivers zero‑success prompt‑injection protection in benchmark tests – what AI engineers need to knowEU Cyber Resilience Act expands software supply‑chain responsibilities for digital product manufacturersTyped Probability Model Jev Shifts AI Output from Text to Structured DecisionsBasin Pipelines per‑stream ingest capacity jumps to 1 GB/s – what engineers need to knowAI‑driven vulnerability management: moving from CVE counts to contextual risk

Critical Sandbox Escape in isolated-vm Enables Host Control Flow Hijacking

AI SummaryPowered by AI

A critical flaw discovered by Endor Labs allows code running inside an isolated-vm sandbox to corrupt host memory and hijack control flow, bypassing the intended isolation boundaries. This vulnerability impacts a widely adopted Node.js library used extensively for safely executing untrusted AI-generated scripts in production automation platforms.

For years, developers have relied on isolated-vm, an open-source Node.js library designed to run untrusted JavaScript within secure boundaries. While this tool was previously considered superior to older alternatives like vm2 because it utilizes a separate V8 Isolate for each sandbox—effectively creating an OS-enforced boundary similar to how browsers isolate tabs—a critical flaw has been identified that undermines these protections.

What Changed: The Nature of the Flaw

The vulnerability, tracked as GHSA-864f-rcv7-6rh4 with a CVE assignment pending, does not break the V8 Isolate itself. Instead, researchers found an issue in the C++ glue code responsible for serializing data across isolation boundaries.

The core mechanism involves ExternalCopy, which is used to safely serialize objects from one isolate heap into another. When transferring a list of elements (the transferList), the constructor performs validation during its first iteration but fails to revalidate those same elements when actually performing the data transfer in subsequent steps.

This creates a Time-of-Check-to-Time-of-Use (TOCTOU) gap. An attacker can register a stateful getter that provides valid memory buffers for initial checks, then supply different content during the unchecked transfer phase. By hijacking this process starting from nothing more than a single ivm.Reference, an adversary inside the sandbox can escalate privileges to corrupt host application memory and execute code on the main thread.

Engineering Impact: AI Agents at Risk

The implications for platform engineering are significant. The source text highlights that isolated-vm is a popular tool, seeing over one million downloads weekly, specifically because it enables running model-generated or user-supplied code safely—a core requirement in the age of autonomous agents.

Many high-profile projects rely on this library to execute untrusted scripts:

  • n8n (workflow automation)
  • Mastra agentic AI framework
  • Screeps MMO environment

If an attacker can trigger a sandbox escape, they gain remote code execution capabilities within the host process. This allows them to crash applications for denial-of-service attacks or fully hijack control flow.

Architecture and Operational Considerations

The vulnerability resides in memory-unsafe C++ glue code rather than JavaScript logic itself. While isolated-vm remains a stronger sandbox primitive, the gap between "the primitive is sound" and "the system is safe" often lies in these binding layers.

For platform teams managing AI agents or automation workflows:

  • Scrutinize how data enters sandboxes: Ensure that any mechanism used to pass objects (like ExternalCopy) does not introduce unchecked state transitions between validation and usage phases.

The fix involves migrating to patched versions 7.0.1 or 6.2.0 on the 6.x line, but practitioners must also audit their sandbox configurations for similar TOCTOU patterns in custom serialization logic.

What This Means For Practitioners

The binding layer around your sandbox deserves first-class security attention as untrusted-code execution becomes mainstream. Do not assume that a strong isolation primitive guarantees safety if the data transfer mechanisms are flawed. Review all code paths where host objects or buffers cross into guest environments, ensuring strict revalidation occurs before any memory is written to.

For teams building AI agents using frameworks like Mastra or n8n, immediate migration and audit of sandbox usage patterns should be prioritized alongside standard dependency updates.

Originally published atDevOps.com