PT-2026-1028 · Unknown+1 · Webassembly Wabt+1
Oneafter
·
Published
2026-01-01
·
Updated
2026-01-06
·
CVE-2025-15412
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WebAssembly wabt versions up to 1.0.39
Description
A security issue exists in WebAssembly wabt, specifically within the
wabt::Decompiler::VarName function located in the /src/repro/wabt/bin/wasm-decompile file of the wasm-decompile component. This can lead to an out-of-bounds read. Local access is required for exploitation. The exploit has been publicly disclosed. The project currently lacks an active maintainer.Recommendations
Versions prior to 1.0.39 should not be used.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Buffer Overflow
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Webassembly Wabt