Bottom line: Security teams must patch isolated-vm to prevent potential hijacking of host control flow and remote code execution.
What's happening: Researchers at Qualys discovered the vulnerability, which was publicly disclosed on June 15, 2023, and patched in isolated-vm version 1.3.0.
What to do: Security teams should immediately update isolated-vm to version 1.3.0 and monitor for suspicious activity.