From b6a7f20f948cb0a2811724c4ce82290da8f8d310 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 18 Apr 2025 15:11:43 +0000 Subject: [PATCH] Publish GHSA-h9w6-f932-gq62 --- .../GHSA-h9w6-f932-gq62.json | 57 +++++++++++++++++++ 1 file changed, 57 insertions(+) create mode 100644 advisories/github-reviewed/2025/04/GHSA-h9w6-f932-gq62/GHSA-h9w6-f932-gq62.json diff --git a/advisories/github-reviewed/2025/04/GHSA-h9w6-f932-gq62/GHSA-h9w6-f932-gq62.json b/advisories/github-reviewed/2025/04/GHSA-h9w6-f932-gq62/GHSA-h9w6-f932-gq62.json new file mode 100644 index 00000000000..618674eb000 --- /dev/null +++ b/advisories/github-reviewed/2025/04/GHSA-h9w6-f932-gq62/GHSA-h9w6-f932-gq62.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h9w6-f932-gq62", + "modified": "2025-04-18T15:10:05Z", + "published": "2025-04-18T15:10:05Z", + "aliases": [ + "CVE-2025-32792" + ], + "summary": "ses's global contour bindings leak into Compartment lexical scope", + "details": "### Impact\n\nWeb pages and web extensions using `ses` and the `Compartment` API to evaluate third-party code in an isolated execution environment that have also elsewhere used `const`, `let`, and `class` bindings in the top-level scope of a `