wasmtime-wasi
crates.io4 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting wasmtime-wasipage 1 of 1
- CVE-2025-53901LOWCVSS 3.5EG 3.5✓ Fixed in 34.0.22025-07-18
Wasmtime is a runtime for WebAssembly. Prior to versions 24.0.4, 33.0.2, and 34.0.2, a bug in Wasmtime's implementation of the WASIp1 set of import functions can lead to a WebAssembly guest inducing a panic in the host (embedder). The spec…
- CVE-2026-47261HIGHCVSS 7.5EG 7.5✓ Fixed in 45.0.02026-06-05
Wasmtime is a runtime for WebAssembly. In versions prior to 24.0.9, 36.0.10, and 44.0.2, when a filesystem preopen is given DirPerms::all() and FilePerms::READ without FilePerms::WRITE, this access control mechanism can be bypassed via the…
- CVE-2026-54786MEDIUMCVSS 5.0EG 5.0✓ Fixed in 45.0.22026-07-01
Wasmtime is a runtime for WebAssembly. All versions prior to 24.0.10; versions 25.0.0 through those before 36.0.11; versions 37.0.0 through those before 44.0.3; and versions 45.0.0 and 45.0.1 contain a native implementation of WASIp1 whic…
- CVE-2026-58494MEDIUMCVSS 6.5EG 6.5✓ Fixed in 46.0.12026-07-08
Wasmtime is a runtime for WebAssembly. Prior to 24.0.11, 36.0.12, 45.0.3, and 46.0.1, wasmtime-wasi hard-link creation and renaming check directory permissions but not matching FilePerms on source and destination preopens, allowing a WASI …
Check whether wasmtime-wasi is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for wasmtime-wasi CVEs against the assets you own.
Start Free Scan →