Skip to content

Build2 publishersReports disagree2 min readPublished Updated

A double-read in isolated-vm turns customer JavaScript into host code execution

GHSA-864f-rcv7-6rh4 lets guest code hand the C++ bindings one type on the first read and a different one on the second. Fixes are in 7.0.1 and 6.2.0.

The Engineer · Build desk

How we use AISend a correction

What happened

  • An advisory tracked as GHSA-864f-rcv7-6rh4 describes isolated JavaScript corrupting the memory of the host Node.js process and taking over its control flow.
  • The trigger is a transferList getter reached through ExternalCopy that returns a normal ArrayBuffer on the first read and an attacker-controlled value on the second.
  • Fixed releases are isolated-vm 7.0.1 and 6.2.0.
  • Products named alongside isolated-vm include n8n, Activepieces and Mastra AI, with workflow or code-execution inputs as the entry point and no end-user action required.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • exposure The reachable material is no longer the isolate but the worker: host-privilege execution, then the credentials and connection destinations the automation platform holds.
  • constraint If you cannot ship the upgrade, the offered fallback is to stop handing references into guest code or switch the feature off, which is the bridge those code nodes exist to cross.
  • decision Teams now have to decide whether past reproducible worker segfaults were stability bugs or attempts, because the quiet version of this leaves nothing to grep for.
  • contradiction The published range and the published patch overlap on the 6.x branch, so a shop pinned at 6.2.x cannot tell from the summary whether it is fixed or affected.

A type check that reads a value twice has not checked anything. The bindings validate what the first read returned and then operate on whatever the second read hands back, which is the part the guest controls [3]. Fixing that means either reading once and holding the result, or re-validating at the point of use; a patch that only tightens the check without collapsing the double read leaves the same shape available anywhere else the bindings ask a JavaScript object a question twice.

The entry condition is worth sitting with. The guest needs untrusted execution inside the isolate plus at least one `ivm.Reference` passed in from the host [4]. That reference is the bridge, and the advisory's own fallback for anyone who cannot upgrade is to stop passing references to untrusted code or to turn the feature off entirely [14]. Read those two together and the sandbox stops looking like a wall with a door in it.

The version guidance does not close cleanly. The affected set is given as 7.0.0 or lower, or 6.x below 6.2.0 [18], while the fixed versions are 7.0.1 and 6.2.0 [13]. Taken literally, "7.0.0 or lower" contains 6.2.0, which the same document lists as the remedy [20]. Anyone pinned on the 6.x line cannot resolve their status from that sentence and has to go to the advisory record itself.

Forensics are thin by design. The basic proof of concept ends in `SIGSEGV` and exit 139 [5], with crash sites near `v8::ArrayBuffer::IsDetachable` [6]. The advanced path does not end in a crash; it ends with guest processing in control of the host process [7]. The write-up also notes that the sequence begins inside guest processing with no network signs, and that any outbound traffic afterwards depends entirely on the payload, with nothing published [8]. So the loud artifact belongs to the attempt that failed, and the quiet one is the case you care about.

On the strength of the evidence: the record reports no observed exploitation in public information, and only proof-of-concept-style `transferList` and getter inputs confirmed internally [15]. It also carries a severity of high [19] while the Endor Labs write-up it points to, dated 20 August 2026, is titled as critical [9], and lists the GHSA identifier with no CVE attached [10]. Investigation guidance names audits of code execution nodes and workers in tools like n8n, worker environment variables, cloud credentials and connection destinations [16]. That is where the value sits, and it always did. What changed is the confidence you can place in the isolate that was drawn between it and the customer's expression field [1].

What to watch

  • Whether a CVE is assigned, and whether n8n, Activepieces or Mastra AI state which isolated-vm version their shipped releases bundle.
  • The first credible report of exploitation beyond a proof of concept, which moves this from crash triage to token rotation.
  • Whether the fix removes the second read or only re-validates it, since a re-check leaves the same pattern available elsewhere in the bindings.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories