Back to blog

Blog Post

Beacon: Searchlight Researchers Uncover JavaScript Sandbox Flaw Enabling RCE in Zendesk and Nuclei

Share on social

Sep 10, 2026

Lorem ipsum

Table of contents

Share on social

Join the newsletter
Beacon: Searchlight Researchers Uncover JavaScript Sandbox Flaw Enabling RCE in Zendesk and Nuclei

Top Story This Week:

Searchlight Researchers Uncover JavaScript Sandbox Flaw Enabling RCE in Zendesk and Nuclei

Searchlight Labs researchers have uncovered a previously unknown vulnerability in Goja, a JavaScript engine written in Go and used by applications including Zendesk, Nuclei, Grafana k6 and PocketBase.

The flaw, found in Goja's implementation of TypedArray methods, could allow an attacker to escape the JavaScript sandbox and execute arbitrary code on the underlying system. The team demonstrated working exploitation against both Zendesk and Nuclei, showing how a subtle vulnerability in an underlying component could become a route to compromise in real-world applications. Patches have since been applied for Zendesk and Nuclei. (Read more on our research center)

Why it Matters

The interesting part of this vulnerability is not just that Goja was vulnerable, but that the component responsible for safely executing untrusted JavaScript could itself become the route to compromise.

Organizations increasingly rely on software to execute code they don't fully control, often assuming that a sandbox provides a strong security boundary. But that boundary is only as secure as the technology implementing it. In this case, a vulnerability several layers beneath the applications using Goja could be turned into code execution on the underlying system. The research is a reminder that an organization's attack surface extends beyond the applications and infrastructure it can see directly, into the components and security mechanisms those systems depend on.

What this Means for Practitioners

Start by understanding where your organization executes untrusted code and what technologies are responsible for containing it. We strongly recommend anyone depending on Goja to update to the latest version, particularly if it's used to sandbox untrusted code.

Searchlight reported the issue to Zendesk and Goja in mid-June. Zendesk responded promptly, submitting a fix that was merged within days.

Don’t assume “sandboxed” means “safe.” Treat the engines and libraries that enforce isolation as part of your attack surface, and patch them promptly when new research or advisories land. A flaw in one of these embedded components may never appear as an obvious vulnerability in the application itself, but can still become a potential path out of the sandbox and across a security boundary.

What this Means for Security Leaders

Just knowing what you're running isn't always enough - you also need to understand what your security depends on.

A vulnerability buried several layers beneath an application can become an attack path without appearing on the traditional perimeter or asset inventory. Security leaders should therefore consider not just the products their organizations operate, but the third-party components, execution environments and security mechanisms those products rely on.

This is also a good example of the value of finding weaknesses before attackers do. The Goja vulnerability was identified, exploited and responsibly disclosed while organizations still had an opportunity to patch. Proactive vulnerability research can turn an unknown attack path into a known risk that defenders can act on – shifting security from responding to exploitation towards preventing it.

Discover More

How Does Continuous Attack Surface Management Protect Your Business?

Continuous attack surface management transforms cybersecurity from reactive to proactive by monitoring your entire digital footprint in real-time, identifying vulnerabilities before attackers can exploit them. In this blog we discuss how continuous Attack Surface Management works and how it protects your business from evolving cyber threats. Read more.

Shadow Exposure: Why Your Most Trusted Software Could Pose Your Biggest Threat

Unlike traditional vulnerabilities that might be identified through a simple patch management list, shadow exposure exists in the blind spots of widely deployed third-party software, VPN appliances, ITSM platforms, and network management tools that organizations trust and rely on for daily operations. Read our blog to discover more about the threats hiding within your assets. Read more.

Lizzie Clark

Author

Lizzie Clark

Marketing Executive at Searchlight Cyber

Lizzie is an experienced IT and cybersecurity marketing professional with six years of specialist experience in the industry. Lizzie produces a range of content - from blogs and long-form articles to newsletters and social media - with a focus on writing that informs and engages technical audiences.

Searchlight's research team finds novel vulnerabilities in enterprise software and turns each into a check the platform runs ahead of public disclosure. You often close the exposure weeks or months before the CVE exists, and before the rest of the market knows to look.

Searchlight doesn't rely on noisy CVE matching, it validates exploitability directly: the actual exploit runs against the exact software version in your environment, and an exposure is confirmed genuinely exploitable before it reaches your team, with the proof of concept attached.

Searchlight removes the delays between stages: hourly scanning identifies exposure the instant it appears, validation happens at the point of discovery so triage isn't needed, findings route directly into your remediation tools with mitigation guidance attached, and retesting confirms closure the moment a fix ships.

Attackers conduct reconnaissance and discuss their targets on hidden parts of the internet before they strike: registering lookalike infrastructure, trading credentials, discussing targets. Searchlight surfaces that activity as it forms and maps it to your organization, so your team acts while a threat is still being assembled, not after it has launched.

Related Blog Posts

September 3, 2026

Beacon: FulcrumSec Claims Responsibility for Manchester Airport Group Breach

September 1, 2026

Searchlight Threat + RST Cloud: Instant insights from 1,000s of threat reports

August 27, 2026

Beacon: North Korean Hackers Linked to Rust Supply Chain Attack

August 20, 2026

Beacon: Cl0p Claims Data Theft from More than 40 Companies

August 19, 2026

wp2shell: Discovering One of 2026’s Biggest Zero-Days, and the Future of Exposure Management

August 14, 2026

Beacon: OpenAI's Astra Paused Due to Hacking Use Concerns

Never miss a beat

Get all news and updates about Searchlight Cyber, directly in your inbox.

Subscribe
Please enter a valid email address.
Background Gradient