Preliminary research
Sandcastles, Not Sandboxes: auditing Pyodide-to-host trust boundaries
Sandcastles, Not Sandboxes: How One Architectural Flaw Exposed Seven Products
AI-collected research leads through 22 September 2026, including targeted additions between broader sweeps. Unranked, incomplete, not community-vetted, and subject to change.
Traces restricted Python execution through ctypes and Emscripten exports into the runtime embedding Pyodide. Product cases separate interpreter restrictions from host capabilities, data and credentials, providing a method for assessing the actual deployment boundary rather than treating WebAssembly alone as an application sandbox.
Record
- Document
- Sandcastles, Not Sandboxes: How One Architectural Flaw Exposed Seven Products
- Researcher
- Vladimir Tokarev and Saar Pearl
- Published by
- Cyera Research
- Date
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Vladimir Tokarev and Saar Pearl, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .