PT-2026-56584 · Bytecode Alliance · Wasmtime
CVE-2026-58494
·
Published
2026-06-24
·
Updated
2026-07-08
CVSS v3.1
6.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Wasmtime versions prior to 24.0.11
Wasmtime versions prior to 36.0.12
Wasmtime versions prior to 45.0.3
Wasmtime versions prior to 46.0.1
Description
In the wasmtime-wasi component, hard-link creation and renaming processes verify directory permissions but fail to match
FilePerms on source and destination preopens. This allows a WASI guest with a read-only source file capability to overwrite host files that are exposed as FilePerms::READ through the wasip1, wasip2, or wasip3 filesystem interfaces.Recommendations
Update to version 24.0.11.
Update to version 36.0.12.
Update to version 45.0.3.
Update to version 46.0.1.
Exploit
Fix
Improper Preservation of Permissions
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wasmtime