PT-2026-56584 · Bytecode Alliance · Wasmtime

CVE-2026-58494

·

Published

2026-06-24

·

Updated

2026-07-08

CVSS v3.1

6.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Wasmtime versions prior to 24.0.11 Wasmtime versions prior to 36.0.12 Wasmtime versions prior to 45.0.3 Wasmtime versions prior to 46.0.1
Description In the wasmtime-wasi component, hard-link creation and renaming processes verify directory permissions but fail to match FilePerms on source and destination preopens. This allows a WASI guest with a read-only source file capability to overwrite host files that are exposed as FilePerms::READ through the wasip1, wasip2, or wasip3 filesystem interfaces.
Recommendations Update to version 24.0.11. Update to version 36.0.12. Update to version 45.0.3. Update to version 46.0.1.

Exploit

Fix

Improper Preservation of Permissions

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-58494
GHSA-4CH3-9J33-3PMJ
RUSTSEC-2026-0188

Affected Products

Wasmtime