CVE-2026-58494

MEDIUM

Wasmtime: WASI hard links bypass wasmtime-wasi's FilePerms for destination

Title source: cna
STIX 2.1

Description

Wasmtime is a runtime for WebAssembly. Prior to 24.0.11, 36.0.12, 45.0.3, and 46.0.1, wasmtime-wasi hard-link creation and renaming check directory permissions but not matching FilePerms on source and destination preopens, allowing a WASI guest with a read-only source file capability to overwrite host files exposed as FilePerms::READ through wasip1, wasip2, or wasip3 filesystem interfaces. This issue is fixed in versions 24.0.11, 36.0.12, 45.0.3, and 46.0.1.

Scores

CVSS v3 6.5
EPSS 0.0012
EPSS Percentile 2.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-281 CWE-863
Status published
Products (4)
bytecodealliance/wasmtime < 24.0.11
bytecodealliance/wasmtime >= 25.0.0, < 36.0.12
bytecodealliance/wasmtime >= 37.0.0, < 45.0.3
bytecodealliance/wasmtime >= 46.0.0, < 46.0.1
Published Jul 08, 2026
Tracked Since Jul 09, 2026