CVE-2025-46687: Bellard Quickjs

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

quickjs-ng through 0.9.0 has a missing length check in JS_ReadString for a string, leading to a heap-based buffer overflow. QuickJS before 2025-04-26 is also affected.

Affected products

  • Bellard Quickjs: before 2025-04-26 (fixed in 2025-04-26)
  • Quickjs-NG Quickjs: up to and including 0.9.0

Published 2025-04-27. Last modified 2026-06-17.