Product
An arbitrary user within a QEMU-based Lima VM can exploit improper access controls on the guest agent Unix socket (/run/lima-guestagent.sock) to execute arbitrary commands with root privileges within the guest VM.