Junglewise Threat Intelligence

CVE-2026-58494: Bytecode Alliance Wasmtime improper permission preservation in wasmtime-wasi

CVE-2026-58494 · Severity: medium · CVSS 6.5 · Published 2026-07-08

Technologies: wasmtime-wasi (crates.io), Bytecode Alliance Wasmtime. Vendors: crates.io.

Executive brief

Wasmtime is a tool used to run WebAssembly applications safely in isolated environments. A security flaw was found where the system failed to properly check permissions when creating file links or renaming files. This could allow a malicious application to overwrite sensitive files on the host computer that it should only have permission to read, potentially leading to unauthorized data modification.

Technical details

A vulnerability exists in wasmtime-wasi's implementation of WASI filesystem interfaces (wasip1, wasip2, and wasip3). The runtime correctly checks directory permissions during hard-link creation and renaming but fails to validate that the FilePerms on the source and destination preopens match. This allows a WASI guest with only read-only capabilities for a source file to create a hard link or rename it to a destination exposed with FilePerms::READ, effectively allowing the guest to overwrite host files. The issue is rooted in improper preservation of permissions (CWE-281) and incorrect authorization (CWE-863). Patches are available in versions 24.0.11, 36.0.12, 45.0.3, and 46.0.1.

Affected products

  • Bytecode Alliance Wasmtime < 24.0.11, >= 25.0.0 < 36.0.12, >= 37.0.0 < 45.0.3, >= 46.0.0 < 46.0.1

Timeline

  • 2026-06-24: patched: Fixes committed to various release branches.
  • 2026-07-08: disclosed: CVE-2026-58494 published.

References

Related threats