CVE-2025-46688: Quickjs-NG Quickjs

High severity, CVSS 8.4. EPSS: 0.3% chance of exploitation in the next 30 days.

quickjs-ng through 0.9.0 has an incorrect size calculation in JS_ReadBigInt for a BigInt, leading to a heap-based buffer overflow. QuickJS before 2025-04-26 is also affected.

Affected products

Published 2025-04-27. Last modified 2026-06-17.