CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2025-15412: wabt through 1.0.39 (inclusive), 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, 1.0.5, 1.0.6, 1.0.7, 1.0.8, 1.0.9, 1.0.10, 1.0.11…

CVE-2025-15412. CVSS 3.1 base score 7.8 (HIGH, NVD). EPSS 0.00208 (percentile 0.09937), scored 2026-10-05.

Affected technology

wabt · through 1.0.39 (inclusive)
webassembly

wabt · 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, 1.0.5, 1.0.6, 1.0.7, 1.0.8, 1.0.9, 1.0.10, 1.0.11, 1.0.12, 1.0.13, 1.0.14, 1.0.15, 1.0.16, 1.0.17, 1.0.18, 1.0.19, 1.0.20, 1.0.21, 1.0.22, 1.0.23, 1.0.24, 1.0.25, 1.0.26, 1.0.27, 1.0.28, 1.0.29, 1.0.30, 1.0.31, 1.0.32, 1.0.33, 1.0.34, 1.0.35, 1.0.36, 1.0.37, 1.0.38, 1.0.39
WebAssembly

Description’s affected range: up to 1.0.39

Component: wasm-decompile
Function: wabt::Decompiler::VarName
File: /src/repro/wabt/bin/wasm-decompile

Attack conditions (VulDB, CVSS 4.0): Local · Low privileges required · No user interaction required

What an attacker can do

VulDB’s CVSS 4.0 assessment (base score 1.9/10) rates confidentiality, integrity and availability impact as low. The description does not specify what an attacker can achieve beyond these rated impacts.

Published

CWE
CWE-119, CWE-125
CCR priority
31.3 /100 (P4)
CVSS 3.1
7.8 /10 · CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H · NVD
EPSS
0.00208 · percentile 0.09994 · 2026-10-06
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2025-15412.html