CVE-2025-46687: Bellard Quickjs
High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.
quickjs-ng through 0.9.0 has a missing length check in JS_ReadString for a string, leading to a heap-based buffer overflow. QuickJS before 2025-04-26 is also affected.
Affected products
- Bellard Quickjs: before 2025-04-26 (fixed in 2025-04-26)
- Quickjs-NG Quickjs: up to and including 0.9.0
Published 2025-04-27. Last modified 2026-06-17.