Executive brief
Wasmtime is a tool used to run WebAssembly applications safely in isolated environments. A security flaw was found where the system failed to properly check permissions when creating file links or renaming files. This could allow a malicious application to overwrite sensitive files on the host computer that it should only have permission to read, potentially leading to unauthorized data modification.
Technical details
A vulnerability exists in wasmtime-wasi's implementation of WASI filesystem interfaces (wasip1, wasip2, and wasip3). The runtime correctly checks directory permissions during hard-link creation and renaming but fails to validate that the FilePerms on the source and destination preopens match. This allows a WASI guest with only read-only capabilities for a source file to create a hard link or rename it to a destination exposed with FilePerms::READ, effectively allowing the guest to overwrite host files. The issue is rooted in improper preservation of permissions (CWE-281) and incorrect authorization (CWE-863). Patches are available in versions 24.0.11, 36.0.12, 45.0.3, and 46.0.1.
Affected products
- Bytecode Alliance Wasmtime < 24.0.11, >= 25.0.0 < 36.0.12, >= 37.0.0 < 45.0.3, >= 46.0.0 < 46.0.1
Timeline
- 2026-06-24: patched: Fixes committed to various release branches.
- 2026-07-08: disclosed: CVE-2026-58494 published.
References
- https://github.com/bytecodealliance/wasmtime/commit/5ddfd5f1ef28f2041fa07d237ad0336e167b0e0c
- https://github.com/bytecodealliance/wasmtime/commit/7db94cdcf0c79cb3dfde884b534b653f2dd83367
- https://github.com/bytecodealliance/wasmtime/commit/8a250aac0962ca1364b5f16525720e9d0b39edcd
- https://github.com/bytecodealliance/wasmtime/commit/d3ceb56ec35f39e02496eeb4e2d9c7f4fb964d9e
- https://github.com/bytecodealliance/wasmtime/releases/tag/v24.0.11
- https://github.com/bytecodealliance/wasmtime/releases/tag/v36.0.12
- https://github.com/bytecodealliance/wasmtime/releases/tag/v45.0.3