CVE-2025-15412
Last modified
CVE-2025-15412 is a low-severity vulnerability rated 1.9/10 on the CVSS scale. A security vulnerability has been detected in WebAssembly wabt up to 1.0.39. This issue affects the function wabt::Decompiler::VarName of the file /src/repro/wabt/bin/wasm-decompile of the component wasm-decompile. EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
A security vulnerability has been detected in WebAssembly wabt up to 1.0.39. This issue affects the function wabt::Decompiler::VarName of the file /src/repro/wabt/bin/wasm-decompile of the component wasm-decompile. Such manipulation leads to out-of-bounds read. Local access is required to approach this attack. The exploit has been disclosed publicly and may be used. Unfortunately, the project has no active maintainer at the moment. In a reply to the issue report somebody recommended to the researcher to provide a PR himself.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Webassembly | Wabt | <= 1.0.39 |
References
- https://github.com/WebAssembly/wabt/issues/2678Exploit, Issue Tracking, Vendor Advisory
- https://vuldb.com/?ctiid.339333Permissions Required, VDB Entry
- https://vuldb.com/?id.339333Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.719826Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2025-15412?
How severe is CVE-2025-15412?
How do I fix CVE-2025-15412?
Are you affected by CVE-2025-15412?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
