CVE-2026-37630

High severity, CVSS 7.3. EPSS: 0.4% chance of exploitation in the next 30 days.

An issue in QuickJS-NG v.0.12.1 allows an attacker to execute arbitrary code via the js_mapped_arguments_mark function

Published 2026-05-11. Last modified 2026-06-17.