Aller au contenu

Fiche vulnérabilité

CVE-2022-25893 : faille critique vm2 project vm2 (CVSS 9.8)

Description

The package vm2 before 3.9.10 are vulnerable to Arbitrary Code Execution due to the usage of prototype lookup for the WeakMap.prototype.set method. Exploiting this vulnerability leads to access to a host object and a sandbox compromise.

En bref

Sévérité
Critique (CVSS 9.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
21 déc. 2022
Dernière mise à jour
17 juin 2026

Produits concernés

  • vm2 project vm2

Références

Rechercher une autre vulnérabilité dans la base CVE