PT-2025-18373 · Ladybird · Ladybird

CVE-2025-47154

·

Published

2025-03-19

·

Updated

2025-06-24

CVSS v3.1

9.0

Critical

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ladybird versions prior to f5a6704
Description The issue is related to a use-after-free vulnerability in LibJS, which is part of the Ladybird browser engine. This vulnerability allows remote attackers to execute arbitrary code via a crafted .js file. The problem arises from the mishandling of the freeing of the vector that arguments list references. The GitHub README for Ladybird notes that it is in a pre-alpha state and is only suitable for use by developers.
Recommendations For Ladybird versions prior to f5a6704, update to a version that includes the fix for this issue, as the current version is vulnerable to remote code execution attacks. As a temporary workaround, consider restricting the execution of .js files from untrusted sources to minimize the risk of exploitation.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-11294
CVE-2025-47154

Affected Products

Ladybird