Skip to content

create rustsec advisory wasmtime-wasi crate: wasmtime project's GHSA-2r75-cxrj-cmph#2906

Merged
djc merged 1 commit into
rustsec:mainfrom
pchickey:wasmtime-GHSA-2r75-cxrj-cmph
May 22, 2026
Merged

create rustsec advisory wasmtime-wasi crate: wasmtime project's GHSA-2r75-cxrj-cmph#2906
djc merged 1 commit into
rustsec:mainfrom
pchickey:wasmtime-GHSA-2r75-cxrj-cmph

Conversation

@pchickey
Copy link
Copy Markdown
Contributor

Affected crate(s)

  • wasmtime-wasi (6,589,947)

Links to upstream issue(s) or PR(s)

Fix in main: bytecodealliance/wasmtime#13429

which contains links to all of the backports to release branch PRs

Security advisory: GHSA-2r75-cxrj-cmph

Severity

Filesystem access control: bug permits truncation and writing to existing files in the filesystem where wasmtime-wasi was configured to provide read-only access.

Checklist

  • Advisory filename(s) starts with RUSTSEC-0000-0000 as the ID
  • date field is set to the public disclosure date
  • Contains a concise and descriptive title after advisory metadata
  • Asked maintainer(s) if publishing an advisory is appropriate

Copy link
Copy Markdown
Member

@djc djc left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks!

@djc djc merged commit 957d00b into rustsec:main May 22, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants