Vulnerability Description
A weakness has been identified in QuickJS up to eb2c89087def1829ed99630cb14b549d7a98408c. This affects the function js_array_buffer_slice of the file quickjs.c. This manipulation causes buffer over-read. The attack is restricted to local execution. The exploit has been made available to the public and could be exploited. This product adopts a rolling release strategy to maintain continuous delivery Patch name: c6fe5a98fd3ef3b7064e6e0145dfebfe12449fea. To fix this issue, it is recommended to deploy a patch.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bellard | Quickjs | < 2025-11-03 |
Related Weaknesses (CWE)
References
- https://github.com/bellard/quickjs/commit/c6fe5a98fd3ef3b7064e6e0145dfebfe12449fPatch
- https://github.com/bellard/quickjs/issues/451ExploitIssue Tracking
- https://github.com/bellard/quickjs/issues/451#issue-3533698042ExploitIssue Tracking
- https://github.com/bellard/quickjs/issues/451#issuecomment-3481807558ExploitIssue Tracking
- https://vuldb.com/?ctiid.331268Permissions RequiredVDB Entry
- https://vuldb.com/?id.331268Third Party AdvisoryVDB Entry
- https://vuldb.com/?submit.678850ExploitThird Party AdvisoryVDB Entry
- https://github.com/bellard/quickjs/issues/451ExploitIssue Tracking
- https://github.com/bellard/quickjs/issues/451#issue-3533698042ExploitIssue Tracking
- https://github.com/bellard/quickjs/issues/451#issuecomment-3481807558ExploitIssue Tracking
FAQ
What is CVE-2025-12745?
CVE-2025-12745 is a vulnerability with a CVSS score of 5.3 (MEDIUM). A weakness has been identified in QuickJS up to eb2c89087def1829ed99630cb14b549d7a98408c. This affects the function js_array_buffer_slice of the file quickjs.c. This manipulation causes buffer over-re...
How severe is CVE-2025-12745?
CVE-2025-12745 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-12745?
Check the references section above for vendor advisories and patch information. Affected products include: Bellard Quickjs.