Junglewise Threat Intelligence

CVE-2025-32792: ses library variable scope leakage in Compartment isolation

CVE-2025-32792 · Severity: medium · CVSS 4 · Published 2025-04-18

Technologies: ses (npm). Vendors: npm.

Executive brief

ses is a JavaScript library that provides secure sandboxing capabilities for running untrusted third-party code in isolated execution environments called Compartments. A flaw in ses versions prior to 1.12.0 allows sensitive top-level variables (defined with let, const, or class) from the host page or extension to leak into the scope accessible by sandboxed third-party code, potentially exposing sensitive data or tokens to attackers.

Technical details

The vulnerability is a scope leakage issue (CWE-497) in ses's Compartment API. The sandboxing mechanism uses a with-block and a semi-opaque scope Proxy to isolate third-party code execution. The proxy previously revealed any named property absent from globalThis to the surrounding lexical scope, leaking host-level bindings (let, const, class declarations) into the isolated environment's scope. Web pages and extensions using both ses Compartments and top-level lexical bindings in <script> tags are affected. The vulnerability requires no user interaction or authentication and is network-accessible in web contexts. Patches are available in ses version 1.12.0 and later, which makes the scope proxy fully opaque to prevent this leakage.

Affected products

  • Endo ses <1.12.0

Timeline

  • 2025-04-17: disclosed
  • 2025-04-18: patched: ses version 1.12.0 released with fix
  • 2025-04-18: advisory

References

Related threats