Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Ghaem Arasteh

#27460of 56,330
9.8Total CVSS
Vulnerabilities · 1
PT-2022-17590
9.8
2022-12-21
Vm2 · Vm2 · CVE-2022-25893
**Name of the Vulnerable Software and Affected Versions** vm2 versions prior to 3.9.10 **Description** The issue is related to Arbitrary Code Execution due to the usage of prototype lookup for the `WeakMap.prototype.set` method. This allows access to a host object and can lead to a sandbox compromise. **Recommendations** For versions prior to 3.9.10, update to version 3.9.10 or later to resolve the issue. As a temporary workaround, consider restricting the usage of the `WeakMap.prototype.set` method until a patch is applied.