Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-21413

29
FAUCET Score

CVE-2021-21413 describes a critical vulnerability in isolated-vm versions prior to v4.0.0, a Node.js library for V8 isolates, where API pitfalls allow attackers to bypass isolation and access the main Node.js isolate's permissions. This vulnerability, rated 9.6 CRITICAL, allows for arbitrary code execution by leveraging exposed Reference instances to gain access to the Node.js context's Function object or NativeModule objects, potentially loading and running native code. There is no evidence of active exploitation, public exploit code, or significant community discussion, suggesting it is not currently a widespread threat.

Impacted Technologies

VendorProductVersion(s)CPE
< 4.0.0CPE matchmatch criteria
cpe:2.3:a:isolated-vm_project:isolated-vm:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 3.1

8.0HIGH

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N

Attack Vector
ADJACENT_NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
1.6
Impact Score
5.8
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.71%
Probability of exploitation in next 30 days
EPSS Percentile
49.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0071 is in the 60th percentile among its peer group of 64 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 1.3 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
npmpatch availablevia ghsa
Product: isolated-vmFixed in: 4.0.0

Vendor Advisories (1)

npmGHSA-mmhj-4w6j-76h7high

Misuse of `Reference` and other transferable APIs may lead to access to nodejs isolate

Apr 6, 2021

References

github.com / laverdet/isolated-vm/blob/main/CHANGELOG.md
Release NotesThird Party Advisory
github.com / laverdet/isolated-vm/commit/2646e6c1558bac66285daeab54c7d490ed332b15
PatchThird Party Advisory
github.com / laverdet/isolated-vm/commit/27151bfecc260e96714443613880e3b2e6596704
PatchThird Party Advisory
github.com / laverdet/isolated-vm/security/advisories/GHSA-mmhj-4w6j-76h7
Third Party Advisory