CVE-2025-32792: ses's global contour bindings leak into Compartment lexical scope
Web pages and web extensions using ses
and the Compartment
API to evaluate third-party code in an isolated execution environment that have also elsewhere used const
, let
, and class
bindings in the top-level scope of a <script>
tag will have inadvertently revealed these bindings in the lexical scope of third-party code.
References
Code Behaviors & Features
Detect and mitigate CVE-2025-32792 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →