CVE-2025-15411
Last modified
CVE-2025-15411 is a low-severity vulnerability rated 1.9/10 on the CVSS scale. A weakness has been identified in WebAssembly wabt up to 1.0.39. This vulnerability affects the function wabt::AST::InsertNode of the file /src/repro/wabt/bin/wasm-decompile of the component wasm-decompile. EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
A weakness has been identified in WebAssembly wabt up to 1.0.39. This vulnerability affects the function wabt::AST::InsertNode of the file /src/repro/wabt/bin/wasm-decompile of the component wasm-decompile. This manipulation causes memory corruption. It is possible to launch the attack on the local host. The exploit has been made available to the public and could be used for attacks. Unfortunately, the project has no active maintainer at the moment. In a reply to the issue report somebody recommended to the researcher to provide a PR himself.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Webassembly | Wabt | <= 1.0.39 |
References
- https://github.com/WebAssembly/wabt/issues/2679Exploit, Issue Tracking, Vendor Advisory
- https://vuldb.com/?ctiid.339332Permissions Required, VDB Entry
- https://vuldb.com/?id.339332Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.719825Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2025-15411?
How severe is CVE-2025-15411?
How do I fix CVE-2025-15411?
Are you affected by CVE-2025-15411?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
