CVE-2021-21413 describes a critical vulnerability in isolated-vm versions prior to v4.0.0, a Node.js library for V8 isolates, where API pitfalls allow attackers to bypass isolation and access the main Node.js isolate's permissions. This vulnerability, rated 9.6 CRITICAL, allows for arbitrary code execution by leveraging exposed Reference instances to gain access to the Node.js context's Function object or NativeModule objects, potentially loading and running native code. There is no evidence of active exploitation, public exploit code, or significant community discussion, suggesting it is not currently a widespread threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.0.0CPE matchmatch criteria | cpe:2.3:a:isolated-vm_project:isolated-vm:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 1.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.