Web Hack List

Preliminary research

Sandcastles, Not Sandboxes: auditing Pyodide-to-host trust boundaries

Sandcastles, Not Sandboxes: How One Architectural Flaw Exposed Seven Products

AI-collected research leads through 22 September 2026, including targeted additions between broader sweeps. Unranked, incomplete, not community-vetted, and subject to change.

Traces restricted Python execution through ctypes and Emscripten exports into the runtime embedding Pyodide. Product cases separate interpreter restrictions from host capabilities, data and credentials, providing a method for assessing the actual deployment boundary rather than treating WebAssembly alone as an application sandbox.

Record

Document
Sandcastles, Not Sandboxes: How One Architectural Flaw Exposed Seven Products
Researcher
Vladimir Tokarev and Saar Pearl
Published by
Cyera Research
Date
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Vladimir Tokarev and Saar Pearl, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .