LIVE NEWSROOM · --:-- · May 25, 2026
A LIBRARY FOR SECURITY RESEARCHERS

CVE DATABASE  /  CVE-2025-46687

CVE-2025-46687

CVSS 5.6 · MEDIUM

Summary

quickjs-ng through 0.9.0 has a missing length check in JS_ReadString for a string, leading to a heap-based buffer overflow. QuickJS before 2025-04-26 is also affected.

CVSS 3.1 breakdown

Base score5.6 (MEDIUM)
VectorCVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L
Attack vectorLOCAL
Attack complexityHIGH
Privileges requiredNONE
User interactionNONE
ScopeCHANGED
ConfidentialityLOW
IntegrityLOW
AvailabilityLOW

Weakness type (CWE)

Affected products

Bellard quickjsQuickjs-ng quickjs
Check this CVE live

Use our free CVE Lookup tool for the latest NVD record, or browse the full CISA KEV catalog.

References

Data: NIST NVD. NVD last modified 2026-01-14. Always verify against the vendor advisory before acting.

Scroll to Top