CVE-2025-46688: Quickjs-NG Quickjs
High severity, CVSS 8.4. EPSS: 0.3% chance of exploitation in the next 30 days.
quickjs-ng through 0.9.0 has an incorrect size calculation in JS_ReadBigInt for a BigInt, leading to a heap-based buffer overflow. QuickJS before 2025-04-26 is also affected.
Affected products
- Quickjs-NG Quickjs: up to and including 0.9.0
- Quickjs Project Quickjs: before 2025-04-26 (fixed in 2025-04-26)
Published 2025-04-27. Last modified 2026-06-17.