By vendor

Bytecodealliance vulnerabilities

Known CVEs affecting Bytecodealliance products, prioritized by severity, with SEC.co remediation and detection guidance.

1 published vulnerability

  • CVE-2026-47261HIGH 7.5

    Wasmtime, a WebAssembly runtime, contains an access control bypass in its filesystem permission enforcement. When a WebAssembly module is granted read-only access to a directory, an attacker can use a specific file-opening technique (the TRUNCATE flag) to bypass those restrictions and modify files that should be protected. The vulnerability exists in versions before 24.0.9, 36.0.10, and 44.0.2, and stems from a missing permission check in the code that handles file opening operations.