CVE-2023-48184: Quickjs Project Quickjs
Low severity, CVSS 3.9. EPSS: 0.3% chance of exploitation in the next 30 days.
QuickJS before 7414e5f has a quickjs.h JS_FreeValueRT use-after-free because of incorrect garbage collection of async functions with closures.
Affected products
- Quickjs Project Quickjs: before 2023-12-27 (fixed in 2023-12-27)
Published 2024-04-23. Last modified 2026-06-17.