Aller au contenu

Fiche vulnérabilité

CVE-2025-15412 : faille élevée webassembly wabt (CVSS 7.8)

Description

A security vulnerability has been detected in WebAssembly wabt up to 1.0.39. This issue affects the function wabt::Decompiler::VarName of the file /src/repro/wabt/bin/wasm-decompile of the component wasm-decompile. Such manipulation leads to out-of-bounds read. Local access is required to approach this attack. The exploit has been disclosed publicly and may be used. Unfortunately, the project has no active maintainer at the moment. In a reply to the issue report somebody recommended to the researcher to provide a PR himself.

En bref

Sévérité
Élevée (CVSS 7.8)
Vecteur CVSS
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
1 janv. 2026
Dernière mise à jour
17 juin 2026

Produits concernés

  • webassembly wabt

Références

Rechercher une autre vulnérabilité dans la base CVE