VDB
KO
MEDIUM 6.5

RUSTSEC-2026-0188

WASI hard links and renames bypass wasmtime-wasi's FilePerms for destination

Details

This is an entry in the RustSec database for the Wasmtime security advisory located at https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-4ch3-9j33-3pmj For more information see the GitHub-hosted security advisory.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io / wasmtime-wasi
Introduced in: 0.0.0-0 Fixed in: 24.0.11

Upgrade wasmtime-wasi to 24.0.11 or newer (ecosystem crates.io).

References