CVE-2026-3979: Quickjs-NG Quickjs
Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.
A flaw has been found in quickjs-ng quickjs up to 0.12.1. This affects the function js_iterator_concat_return of the file quickjs.c. This manipulation causes use after free. The attack requires local access. The exploit has been published and may be used. Patch name: daab4ad4bae4ef071ed0294618d6244e92def4cd. Applying a patch is the recommended action to fix this issue.
Affected products
- Quickjs-NG Quickjs: version 0.12.0 only; version 0.12.1 only
Published 2026-03-12. Last modified 2026-06-17.