Search

Find a vulnerability

Search criteria

    Related vulnerabilities

    CVE-2026-58494 (GCVE-0-2026-58494)

    Vulnerability from cvelistv5 – Published: 2026-07-08 20:22 – Updated: 2026-07-09 13:28
    VLAI
    Title
    Wasmtime: WASI hard links bypass wasmtime-wasi's FilePerms for destination
    Summary
    Wasmtime is a runtime for WebAssembly. Prior to 24.0.11, 36.0.12, 45.0.3, and 46.0.1, wasmtime-wasi hard-link creation and renaming check directory permissions but not matching FilePerms on source and destination preopens, allowing a WASI guest with a read-only source file capability to overwrite host files exposed as FilePerms::READ through wasip1, wasip2, or wasip3 filesystem interfaces. This issue is fixed in versions 24.0.11, 36.0.12, 45.0.3, and 46.0.1.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-07-09 13:28 UTC
    CWE
    • CWE-281 - Improper Preservation of Permissions
    • CWE-863 - Incorrect Authorization
    Impacted products
    Vendor Product Version
    bytecodealliance wasmtime Affected: < 24.0.11
    Affected: >= 25.0.0, < 36.0.12
    Affected: >= 37.0.0, < 45.0.3
    Affected: >= 46.0.0, < 46.0.1
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-58494",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-07-09T13:28:46.718754Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-07-09T13:28:57.055Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "wasmtime",
              "vendor": "bytecodealliance",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 24.0.11"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 25.0.0, \u003c 36.0.12"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 37.0.0, \u003c 45.0.3"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 46.0.0, \u003c 46.0.1"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Wasmtime is a runtime for WebAssembly. Prior to 24.0.11, 36.0.12, 45.0.3, and 46.0.1, wasmtime-wasi hard-link creation and renaming check directory permissions but not matching FilePerms on source and destination preopens, allowing a WASI guest with a read-only source file capability to overwrite host files exposed as FilePerms::READ through wasip1, wasip2, or wasip3 filesystem interfaces. This issue is fixed in versions 24.0.11, 36.0.12, 45.0.3, and 46.0.1."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "NONE",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-281",
                  "description": "CWE-281: Improper Preservation of Permissions",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-863",
                  "description": "CWE-863: Incorrect Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-07-08T20:22:16.039Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-4ch3-9j33-3pmj",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-4ch3-9j33-3pmj"
            },
            {
              "name": "https://github.com/bytecodealliance/wasmtime/commit/5ddfd5f1ef28f2041fa07d237ad0336e167b0e0c",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/bytecodealliance/wasmtime/commit/5ddfd5f1ef28f2041fa07d237ad0336e167b0e0c"
            },
            {
              "name": "https://github.com/bytecodealliance/wasmtime/commit/7db94cdcf0c79cb3dfde884b534b653f2dd83367",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/bytecodealliance/wasmtime/commit/7db94cdcf0c79cb3dfde884b534b653f2dd83367"
            },
            {
              "name": "https://github.com/bytecodealliance/wasmtime/commit/8a250aac0962ca1364b5f16525720e9d0b39edcd",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/bytecodealliance/wasmtime/commit/8a250aac0962ca1364b5f16525720e9d0b39edcd"
            },
            {
              "name": "https://github.com/bytecodealliance/wasmtime/commit/d3ceb56ec35f39e02496eeb4e2d9c7f4fb964d9e",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/bytecodealliance/wasmtime/commit/d3ceb56ec35f39e02496eeb4e2d9c7f4fb964d9e"
            },
            {
              "name": "https://github.com/bytecodealliance/wasmtime/releases/tag/v24.0.11",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/bytecodealliance/wasmtime/releases/tag/v24.0.11"
            },
            {
              "name": "https://github.com/bytecodealliance/wasmtime/releases/tag/v36.0.12",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/bytecodealliance/wasmtime/releases/tag/v36.0.12"
            },
            {
              "name": "https://github.com/bytecodealliance/wasmtime/releases/tag/v45.0.3",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/bytecodealliance/wasmtime/releases/tag/v45.0.3"
            },
            {
              "name": "https://github.com/bytecodealliance/wasmtime/releases/tag/v46.0.1",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/bytecodealliance/wasmtime/releases/tag/v46.0.1"
            }
          ],
          "source": {
            "advisory": "GHSA-4ch3-9j33-3pmj",
            "discovery": "UNKNOWN"
          },
          "title": "Wasmtime: WASI hard links bypass wasmtime-wasi\u0027s FilePerms for destination"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-58494",
        "datePublished": "2026-07-08T20:22:16.039Z",
        "dateReserved": "2026-06-30T20:21:25.812Z",
        "dateUpdated": "2026-07-09T13:28:57.055Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    RUSTSEC-2026-0188 (GHSA-4CH3-9J33-3PMJ)

    Vulnerability from osv_rustsec – Published: 2026-06-24 12:00 – Updated: 2026-07-13 17:31 – Source website
    VLAI
    Summary
    WASI hard links and renames bypass wasmtime-wasi's FilePerms for destination
    Details

    This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-4ch3-9j33-3pmj For more information see the GitHub-hosted security advisory.


    {
      "affected": [
        {
          "database_specific": {
            "categories": [],
            "cvss": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N",
            "informational": null
          },
          "ecosystem_specific": {
            "affected_functions": null,
            "affects": {
              "arch": [],
              "functions": [],
              "os": []
            }
          },
          "package": {
            "ecosystem": "crates.io",
            "name": "wasmtime-wasi",
            "purl": "pkg:cargo/wasmtime-wasi"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0.0.0-0"
                },
                {
                  "fixed": "24.0.11"
                },
                {
                  "introduced": "25.0.0"
                },
                {
                  "fixed": "36.0.12"
                },
                {
                  "introduced": "37.0.0"
                },
                {
                  "fixed": "45.0.3"
                },
                {
                  "introduced": "46.0.0"
                },
                {
                  "fixed": "46.0.1"
                }
              ],
              "type": "SEMVER"
            }
          ],
          "versions": []
        }
      ],
      "aliases": [
        "GHSA-4ch3-9j33-3pmj",
        "CVE-2026-58494"
      ],
      "database_specific": {
        "license": "CC0-1.0"
      },
      "details": "This is an entry in the RustSec database for the Wasmtime security advisory\nlocated at\nhttps://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-4ch3-9j33-3pmj\nFor more information see the GitHub-hosted security advisory.",
      "id": "RUSTSEC-2026-0188",
      "modified": "2026-07-13T17:31:41Z",
      "published": "2026-06-24T12:00:00Z",
      "references": [
        {
          "type": "PACKAGE",
          "url": "https://crates.io/crates/wasmtime-wasi"
        },
        {
          "type": "ADVISORY",
          "url": "https://rustsec.org/advisories/RUSTSEC-2026-0188.html"
        },
        {
          "type": "ADVISORY",
          "url": "https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-4ch3-9j33-3pmj"
        }
      ],
      "related": [],
      "severity": [
        {
          "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N",
          "type": "CVSS_V3"
        }
      ],
      "summary": "WASI hard links and renames bypass wasmtime-wasi\u0027s FilePerms for destination"
    }