VulnerabilityAnalyzed
CVE-2025-46688
quickjs-ng through 0.9.0 has an incorrect size calculation in JS_ReadBigInt for a BigInt, leading to a heap-based buffer overflow.
HIGH 8.4EPSS 0.31%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.31%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
quickjs-ng through 0.9.0 has an incorrect size calculation in JS_ReadBigInt for a BigInt, leading to a heap-based buffer overflow. QuickJS before 2025-04-26 is also affected.
- CVSS 3.1
- 8.4 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.31% probability · 24th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-131
- Affected
- quickjs-ng/quickjs · quickjs project/quickjs
- Source
- cve@mitre.org
References
- https://bellard.org/quickjs/ChangelogProduct
- https://github.com/bellard/quickjs/commit/1eb05e44fad89daafa8ee3eb74b8520b4a37ec9aPatch
- https://github.com/bellard/quickjs/issues/399Exploit, Third Party Advisory
- https://github.com/quickjs-ng/quickjs/commit/28fa43d3ddff2c1ba91b6e3a788b2d7ba82d1465Patch
- https://github.com/quickjs-ng/quickjs/issues/1018Third Party Advisory
- https://github.com/quickjs-ng/quickjs/pull/1020Patch
- https://github.com/quickjs-ng/quickjs/issues/1018Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.