Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Ghaem Arasteh

#24383of 53,633
9.8Total CVSS
Vulnerabilities · 1
PT-2022-17590
9.8
2022-12-21
Vm2 · Vm2 · CVE-2022-25893
**Name of the Vulnerable Software and Affected Versions** vm2 versions prior to 3.9.10 **Description** The issue is related to Arbitrary Code Execution due to the usage of prototype lookup for the `WeakMap.prototype.set` method. This allows access to a host object and can lead to a sandbox compromise. **Recommendations** For versions prior to 3.9.10, update to version 3.9.10 or later to resolve the issue. As a temporary workaround, consider restricting the usage of the `WeakMap.prototype.set` method until a patch is applied.