Vulnerability Description
Wasmtime is a runtime for WebAssembly. Prior to 24.0.11, 36.0.12, 45.0.3, and 46.0.1, wasmtime-wasi hard-link creation and renaming check directory permissions but not matching FilePerms on source and destination preopens, allowing a WASI guest with a read-only source file capability to overwrite host files exposed as FilePerms::READ through wasip1, wasip2, or wasip3 filesystem interfaces. This issue is fixed in versions 24.0.11, 36.0.12, 45.0.3, and 46.0.1.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/bytecodealliance/wasmtime/commit/5ddfd5f1ef28f2041fa07d237ad0
- https://github.com/bytecodealliance/wasmtime/commit/7db94cdcf0c79cb3dfde884b534b
- https://github.com/bytecodealliance/wasmtime/commit/8a250aac0962ca1364b5f1652572
- https://github.com/bytecodealliance/wasmtime/commit/d3ceb56ec35f39e02496eeb4e2d9
- https://github.com/bytecodealliance/wasmtime/releases/tag/v24.0.11
- https://github.com/bytecodealliance/wasmtime/releases/tag/v36.0.12
- https://github.com/bytecodealliance/wasmtime/releases/tag/v45.0.3
- https://github.com/bytecodealliance/wasmtime/releases/tag/v46.0.1
- https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-4ch3-9j33-
FAQ
What is CVE-2026-58494?
CVE-2026-58494 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Wasmtime is a runtime for WebAssembly. Prior to 24.0.11, 36.0.12, 45.0.3, and 46.0.1, wasmtime-wasi hard-link creation and renaming check directory permissions but not matching FilePerms on source and...
How severe is CVE-2026-58494?
CVE-2026-58494 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-58494?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.