Share on social
Sep 10, 2026
Lorem ipsum

Top Story This Week:
Searchlight Researchers Uncover JavaScript Sandbox Flaw Enabling RCE in Zendesk and Nuclei
Searchlight Labs researchers have uncovered a previously unknown vulnerability in Goja, a JavaScript engine written in Go and used by applications including Zendesk, Nuclei, Grafana k6 and PocketBase.
The flaw, found in Goja's implementation of TypedArray methods, could allow an attacker to escape the JavaScript sandbox and execute arbitrary code on the underlying system. The team demonstrated working exploitation against both Zendesk and Nuclei, showing how a subtle vulnerability in an underlying component could become a route to compromise in real-world applications. Patches have since been applied for Zendesk and Nuclei. (Read more on our research center)
Why it Matters
The interesting part of this vulnerability is not just that Goja was vulnerable, but that the component responsible for safely executing untrusted JavaScript could itself become the route to compromise.
Organizations increasingly rely on software to execute code they don't fully control, often assuming that a sandbox provides a strong security boundary. But that boundary is only as secure as the technology implementing it. In this case, a vulnerability several layers beneath the applications using Goja could be turned into code execution on the underlying system. The research is a reminder that an organization's attack surface extends beyond the applications and infrastructure it can see directly, into the components and security mechanisms those systems depend on.
What this Means for Practitioners
Start by understanding where your organization executes untrusted code and what technologies are responsible for containing it. We strongly recommend anyone depending on Goja to update to the latest version, particularly if it's used to sandbox untrusted code.
Searchlight reported the issue to Zendesk and Goja in mid-June. Zendesk responded promptly, submitting a fix that was merged within days.
Don’t assume “sandboxed” means “safe.” Treat the engines and libraries that enforce isolation as part of your attack surface, and patch them promptly when new research or advisories land. A flaw in one of these embedded components may never appear as an obvious vulnerability in the application itself, but can still become a potential path out of the sandbox and across a security boundary.
What this Means for Security Leaders
Just knowing what you're running isn't always enough - you also need to understand what your security depends on.
A vulnerability buried several layers beneath an application can become an attack path without appearing on the traditional perimeter or asset inventory. Security leaders should therefore consider not just the products their organizations operate, but the third-party components, execution environments and security mechanisms those products rely on.
This is also a good example of the value of finding weaknesses before attackers do. The Goja vulnerability was identified, exploited and responsibly disclosed while organizations still had an opportunity to patch. Proactive vulnerability research can turn an unknown attack path into a known risk that defenders can act on – shifting security from responding to exploitation towards preventing it.
Discover More
How Does Continuous Attack Surface Management Protect Your Business?
Continuous attack surface management transforms cybersecurity from reactive to proactive by monitoring your entire digital footprint in real-time, identifying vulnerabilities before attackers can exploit them. In this blog we discuss how continuous Attack Surface Management works and how it protects your business from evolving cyber threats. Read more.
Shadow Exposure: Why Your Most Trusted Software Could Pose Your Biggest Threat
Unlike traditional vulnerabilities that might be identified through a simple patch management list, shadow exposure exists in the blind spots of widely deployed third-party software, VPN appliances, ITSM platforms, and network management tools that organizations trust and rely on for daily operations. Read our blog to discover more about the threats hiding within your assets. Read more.
Searchlight's research team finds novel vulnerabilities in enterprise software and turns each into a check the platform runs ahead of public disclosure. You often close the exposure weeks or months before the CVE exists, and before the rest of the market knows to look.
Searchlight doesn't rely on noisy CVE matching, it validates exploitability directly: the actual exploit runs against the exact software version in your environment, and an exposure is confirmed genuinely exploitable before it reaches your team, with the proof of concept attached.
Searchlight removes the delays between stages: hourly scanning identifies exposure the instant it appears, validation happens at the point of discovery so triage isn't needed, findings route directly into your remediation tools with mitigation guidance attached, and retesting confirms closure the moment a fix ships.
Attackers conduct reconnaissance and discuss their targets on hidden parts of the internet before they strike: registering lookalike infrastructure, trading credentials, discussing targets. Searchlight surfaces that activity as it forms and maps it to your organization, so your team acts while a threat is still being assembled, not after it has launched.







