Medium severity6.5NVD Advisory· Published Jul 8, 2026· Updated Jul 10, 2026
CVE-2026-58494
CVE-2026-58494
Description
Wasmtime is a runtime for WebAssembly. Prior to 24.0.11, 36.0.12, 45.0.3, and 46.0.1, wasmtime-wasi hard-link creation and renaming check directory permissions but not matching FilePerms on source and destination preopens, allowing a WASI guest with a read-only source file capability to overwrite host files exposed as FilePerms::READ through wasip1, wasip2, or wasip3 filesystem interfaces. This issue is fixed in versions 24.0.11, 36.0.12, 45.0.3, and 46.0.1.
Affected products
1- Range: pre 24.0.11, 36.0.12, 45.0.3, and 46.0.1
Patches
Vulnerability mechanics
References
9- github.com/bytecodealliance/wasmtime/commit/5ddfd5f1ef28f2041fa07d237ad0336e167b0e0cnvd
- github.com/bytecodealliance/wasmtime/commit/7db94cdcf0c79cb3dfde884b534b653f2dd83367nvd
- github.com/bytecodealliance/wasmtime/commit/8a250aac0962ca1364b5f16525720e9d0b39edcdnvd
- github.com/bytecodealliance/wasmtime/commit/d3ceb56ec35f39e02496eeb4e2d9c7f4fb964d9envd
- github.com/bytecodealliance/wasmtime/releases/tag/v24.0.11nvd
- github.com/bytecodealliance/wasmtime/releases/tag/v36.0.12nvd
- github.com/bytecodealliance/wasmtime/releases/tag/v45.0.3nvd
- github.com/bytecodealliance/wasmtime/releases/tag/v46.0.1nvd
- github.com/bytecodealliance/wasmtime/security/advisories/GHSA-4ch3-9j33-3pmjnvd
News mentions
0No linked articles in our index yet.