CVE-2026-58494: Bytecodealliance Wasmtime
Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.
Wasmtime is a runtime for WebAssembly. Prior to 24.0.11, 36.0.12, 45.0.3, and 46.0.1, wasmtime-wasi hard-link creation and renaming check directory permissions but not matching FilePerms on source and destination preopens, allowing a WASI guest with a read-only source file capability to overwrite host files exposed as FilePerms::READ through wasip1, wasip2, or wasip3 filesystem interfaces. This issue is fixed in versions 24.0.11, 36.0.12, 45.0.3, and 46.0.1.
Affected products
- Bytecodealliance Wasmtime: before 24.0.11 (fixed in 24.0.11); from 25.0.0, before 36.0.12 (fixed in 36.0.12); from 37.0.0, before 45.0.3 (fixed in 45.0.3); from 46.0.0, before 46.0.1 (fixed in 46.0.1)
Published 2026-07-08. Last modified 2026-07-10.