cbcvebase.
CVE-2026-58494
published 2026-07-08

CVE-2026-58494: Wasmtime is a runtime for WebAssembly. Prior to 24.0.11, 36.0.12, 45.0.3, and 46.0.1, wasmtime-wasi hard-link creation and renaming check directory permissions…

PriorityP432medium6.5CVSS 3.1
AVLACLPRLUINSCCNIHAN
EPSS
0.17%
6.6th percentile
Wasmtime is a runtime for WebAssembly. Prior to 24.0.11, 36.0.12, 45.0.3, and 46.0.1, wasmtime-wasi hard-link creation and renaming check directory permissions but not matching FilePerms on source and destination preopens, allowing a WASI guest with a read-only source file capability to overwrite host files exposed as FilePerms::READ through wasip1, wasip2, or wasip3 filesystem interfaces. This issue is fixed in versions 24.0.11, 36.0.12, 45.0.3, and 46.0.1.

Affected

6 ranges
VendorProductVersion rangeFixed in
bytecodealliancewasmtime< 24.0.1124.0.11
bytecodealliancewasmtime
bytecodealliancewasmtime
bytecodealliancewasmtime
rhcl-1wasm-shim-rhel9
rust-langrust

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.