A weakness has been identified in WebAssembly wabt up to 1.0.39. This vulnerability affects the function wabt::AST::InsertNode of the file /src/repro/wabt/bin/wasm-decompile of the component wasm-decompile. This manipulation causes memory corruption. It is possible to launch the attack on the local host. The exploit has been made available to the public and could be used for attacks. Unfortunately, the project has no active maintainer at the moment. In a reply to the issue report somebody recommended to the researcher to provide a PR himself.

zetlyn/cve-nvd vulnerability cve CVE-2025-15411 cpe cpe:2.3:a:webassembly:wabt:*:*:*:*:*:*:*:* known 2026-01-01

https://nvd.nist.gov/vuln/detail/CVE-2025-15411

Properties

cvss5.3
receipt
Source
NVD
Its words
5.3
Read by
field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-04 18:16 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "cpes": [
              "cpe:2.3:a:webassembly:wabt:*:*:*:*:*:*:*:*"
            ],
            "modules": [
              "wasm-decompile"
            ],
            "product": "wabt",
            "vendor": "WebAssembly",
            "versions": [
              {
                "status": "affected",
                "version": "1.0.0"
              },
              {
                "status": "affected",
                "version": "1.0.1"
              },
              {
                "status": "affected",
                "version": "1.0.2"
              },
              {
                "status": "affected",
                "version": "1.0.3"
              },
              {
                "status": "affected",
                "version": "1.0.4"
              },
              {
                "status": "affected",
                "version": "1.0.5"
              },
              {
                "status": "affected",
                "version": "1.0.6"
              },
              {
                "status": "affected",
                "version": "1.0.7"
              },
              {
                "status": "affected",
                "version": "1.0.8"
              },
              {
                "status": "affected",
                "version": "1.0.9"
              },
              {
                "status": "affected",
                "version": "1.0.10"
              },
              {
                "status": "affected",
                "version": "1.0.11"
              },
              {
                "status": "affected",
                "version": "1.0.12"
              },
              {
                "status": "affected",
                "version": "1.0.13"
              },
              {
                "status": "affected",
                "version": "1.0.14"
              },
              {
                "status": "affected",
                "version": "1.0.15"
              },
              {
                "status": "affected",
                "version": "1.0.16"
              },
              {
                "status": "affected",
                "version": "1.0.17"
              },
              {
                "status": "affected",
                "version": "1.0.18"
              },
              {
                "status": "affected",
                "version": "1.0.19"
              },
              {
                "status": "affected",
                "version": "1.0.20"
              },
              {
                "status": "affected",
                "version": "1.0.21"
              },
              {
                "status": "affected",
                "version": "1.0.22"
              },
              {
                "status": "affected",
                "version": "1.0.23"
              },
              {
                "status": "affected",
                "version": "1.0.24"
              },
              {
                "status": "affected",
                "version": "1.0.25"
              },
              {
                "status": "affected",
                "version": "1.0.26"
              },
              {
                "status": "affected",
                "version": "1.0.27"
              },
              {
                "status": "affected",
                "version": "1.0.28"
              },
              {
                "status": "affected",
                "version": "1.0.29"
              },
              {
                "status": "affected",
                "version": "1.0.30"
              },
              {
                "status": "affected",
                "version": "1.0.31"
              },
              {
                "status": "affected",
                "version": "1.0.32"
              },
              {
                "status": "affected",
                "version": "1.0.33"
              },
              {
                "status": "affected",
                "version": "1.0.34"
              },
              {
                "status": "affected",
                "version": "1.0.35"
              },
              {
                "status": "affected",
                "version": "1.0.36"
              },
              {
                "status": "affected",
                "version": "1.0.37"
              },
              {
                "status": "affected",
                "version": "1.0.38"
              },
              {
                "status": "affected",
                "version": "1.0.39"
              }
            ]
          }
        ],
        "source": "cna@vuldb.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:webassembly:wabt:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "4553C1EF-0407-4632-ACA5-3D1E2A76FBDA",
                "versionEndIncluding": "1.0.39",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A weakness has been identified in WebAssembly wabt up to 1.0.39. This vulnerability affects the function wabt::AST::InsertNode of the file /src/repro/wabt/bin/wasm-decompile of the component wasm-decompile. This manipulation causes memory corruption. It is possible to launch the attack on the local host. The exploit has been made available to the public and could be used for attacks. Unfortunately, the project has no active maintainer at the moment. In a reply to the issue report somebody recommended to the researcher to provide a PR himself."
      },
      {
        "lang": "es",
        "value": "Se ha identificado una debilidad en WebAssembly wabt hasta la versión 1.0.39. Esta vulnerabilidad afecta la función wabt::AST::InsertNode del archivo /src/repro/wabt/bin/wasm-decompile del componente wasm-decompile. Esta manipulación causa corrupción de memoria. Es posible lanzar el ataque en el host local. El exploit se ha puesto a disposición del público y podría usarse para ataques. Desafortunadamente, el proyecto no tiene ningún mantenedor activo en este momento. En una respuesta al informe del problema, alguien recomendó al investigador que proporcionara un PR él mismo."
      }
    ],
    "id": "CVE-2025-15411",
    "lastModified": "2026-10-01T08:10:00.183",
    "metrics": {
      "cvssMetricV2": [
        {
          "acInsufInfo": false,
          "baseSeverity": "MEDIUM",
          "cvssData": {
            "accessComplexity": "LOW",
            "accessVector": "LOCAL",
            "authentication": "SINGLE",
            "availabilityImpact": "PARTIAL",
            "baseScore": 4.3,
            "confidentialityImpact": "PARTIAL",
            "integrityImpact": "PARTIAL",
            "vectorString": "AV:L/AC:L/Au:S/C:P/I:P/A:P",
            "version": "2.0"
          },
          "exploitabilityScore": 3.1,
          "impactScore": 6.4,
          "obtainAllPrivilege": false,
          "obtainOtherPrivilege": false,
          "obtainUserPrivilege": false,
          "source": "cna@vuldb.com",
          "type": "Secondary",
          "userInteractionRequired": false
        }
      ],
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "LOW",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 3.4,
          "source": "cna@vuldb.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "LOCAL",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 1.9,
            "baseSeverity": "LOW",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "PROOF_OF_CONCEPT",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "LOW",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "LOW",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "cna@vuldb.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-15411",
            "options": [
              {
                "exploitation": "poc"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-01-05T21:03:24.165884Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-01-01T20:15:40.640",
    "references": [
      {
        "source": "cna@vuldb.com",
        "url": "https://github.com/WebAssembly/wabt/"
      },
      {
        "source": "cna@vuldb.com",
        "tags": [
          "Exploit",
          "Issue Tracking",
          "Vendor Advisory"
        ],
        "url": "https://github.com/WebAssembly/wabt/issues/2679"
      },
      {
        "source": "cna@vuldb.com",
        "tags": [
          "Exploit"
        ],
        "url": "https://github.com/oneafter/1208/blob/main/af1"
      },
      {
        "source": "cna@vuldb.com",
        "tags": [
          "Permissions Required",
          "VDB Entry"
        ],
        "url": "https://vuldb.com/?ctiid.339332"
      },
      {
        "source": "cna@vuldb.com",
        "tags": [
          "Third Party Advisory",
          "VDB Entry"
        ],
        "url": "https://vuldb.com/?id.339332"
      },
      {
        "source": "cna@vuldb.com",
        "tags": [
          "Third Party Advisory",
          "VDB Entry"
        ],
        "url": "https://vuldb.com/?submit.719825"
      },
      {
        "source": "cna@vuldb.com",
        "url": "https://vuldb.com/?submit.736404"
      }
    ],
    "sourceIdentifier": "cna@vuldb.com",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-119"
          }
        ],
        "source": "cna@vuldb.com",
        "type": "Secondary"
      }
    ]
  }
}
productwabt
receipt
Source
NVD
Its words
wabt
Read by
field:cve.affected[].affectedData[].product
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-04 18:16 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "cpes": [
              "cpe:2.3:a:webassembly:wabt:*:*:*:*:*:*:*:*"
            ],
            "modules": [
              "wasm-decompile"
            ],
            "product": "wabt",
            "vendor": "WebAssembly",
            "versions": [
              {
                "status": "affected",
                "version": "1.0.0"
              },
              {
                "status": "affected",
                "version": "1.0.1"
              },
              {
                "status": "affected",
                "version": "1.0.2"
              },
              {
                "status": "affected",
                "version": "1.0.3"
              },
              {
                "status": "affected",
                "version": "1.0.4"
              },
              {
                "status": "affected",
                "version": "1.0.5"
              },
              {
                "status": "affected",
                "version": "1.0.6"
              },
              {
                "status": "affected",
                "version": "1.0.7"
              },
              {
                "status": "affected",
                "version": "1.0.8"
              },
              {
                "status": "affected",
                "version": "1.0.9"
              },
              {
                "status": "affected",
                "version": "1.0.10"
              },
              {
                "status": "affected",
                "version": "1.0.11"
              },
              {
                "status": "affected",
                "version": "1.0.12"
              },
              {
                "status": "affected",
                "version": "1.0.13"
              },
              {
                "status": "affected",
                "version": "1.0.14"
              },
              {
                "status": "affected",
                "version": "1.0.15"
              },
              {
                "status": "affected",
                "version": "1.0.16"
              },
              {
                "status": "affected",
                "version": "1.0.17"
              },
              {
                "status": "affected",
                "version": "1.0.18"
              },
              {
                "status": "affected",
                "version": "1.0.19"
              },
              {
                "status": "affected",
                "version": "1.0.20"
              },
              {
                "status": "affected",
                "version": "1.0.21"
              },
              {
                "status": "affected",
                "version": "1.0.22"
              },
              {
                "status": "affected",
                "version": "1.0.23"
              },
              {
                "status": "affected",
                "version": "1.0.24"
              },
              {
                "status": "affected",
                "version": "1.0.25"
              },
              {
                "status": "affected",
                "version": "1.0.26"
              },
              {
                "status": "affected",
                "version": "1.0.27"
              },
              {
                "status": "affected",
                "version": "1.0.28"
              },
              {
                "status": "affected",
                "version": "1.0.29"
              },
              {
                "status": "affected",
                "version": "1.0.30"
              },
              {
                "status": "affected",
                "version": "1.0.31"
              },
              {
                "status": "affected",
                "version": "1.0.32"
              },
              {
                "status": "affected",
                "version": "1.0.33"
              },
              {
                "status": "affected",
                "version": "1.0.34"
              },
              {
                "status": "affected",
                "version": "1.0.35"
              },
              {
                "status": "affected",
                "version": "1.0.36"
              },
              {
                "status": "affected",
                "version": "1.0.37"
              },
              {
                "status": "affected",
                "version": "1.0.38"
              },
              {
                "status": "affected",
                "version": "1.0.39"
              }
            ]
          }
        ],
        "source": "cna@vuldb.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:webassembly:wabt:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "4553C1EF-0407-4632-ACA5-3D1E2A76FBDA",
                "versionEndIncluding": "1.0.39",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A weakness has been identified in WebAssembly wabt up to 1.0.39. This vulnerability affects the function wabt::AST::InsertNode of the file /src/repro/wabt/bin/wasm-decompile of the component wasm-decompile. This manipulation causes memory corruption. It is possible to launch the attack on the local host. The exploit has been made available to the public and could be used for attacks. Unfortunately, the project has no active maintainer at the moment. In a reply to the issue report somebody recommended to the researcher to provide a PR himself."
      },
      {
        "lang": "es",
        "value": "Se ha identificado una debilidad en WebAssembly wabt hasta la versión 1.0.39. Esta vulnerabilidad afecta la función wabt::AST::InsertNode del archivo /src/repro/wabt/bin/wasm-decompile del componente wasm-decompile. Esta manipulación causa corrupción de memoria. Es posible lanzar el ataque en el host local. El exploit se ha puesto a disposición del público y podría usarse para ataques. Desafortunadamente, el proyecto no tiene ningún mantenedor activo en este momento. En una respuesta al informe del problema, alguien recomendó al investigador que proporcionara un PR él mismo."
      }
    ],
    "id": "CVE-2025-15411",
    "lastModified": "2026-10-01T08:10:00.183",
    "metrics": {
      "cvssMetricV2": [
        {
          "acInsufInfo": false,
          "baseSeverity": "MEDIUM",
          "cvssData": {
            "accessComplexity": "LOW",
            "accessVector": "LOCAL",
            "authentication": "SINGLE",
            "availabilityImpact": "PARTIAL",
            "baseScore": 4.3,
            "confidentialityImpact": "PARTIAL",
            "integrityImpact": "PARTIAL",
            "vectorString": "AV:L/AC:L/Au:S/C:P/I:P/A:P",
            "version": "2.0"
          },
          "exploitabilityScore": 3.1,
          "impactScore": 6.4,
          "obtainAllPrivilege": false,
          "obtainOtherPrivilege": false,
          "obtainUserPrivilege": false,
          "source": "cna@vuldb.com",
          "type": "Secondary",
          "userInteractionRequired": false
        }
      ],
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "LOW",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 3.4,
          "source": "cna@vuldb.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "LOCAL",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 1.9,
            "baseSeverity": "LOW",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "PROOF_OF_CONCEPT",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "LOW",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "LOW",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "cna@vuldb.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-15411",
            "options": [
              {
                "exploitation": "poc"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-01-05T21:03:24.165884Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-01-01T20:15:40.640",
    "references": [
      {
        "source": "cna@vuldb.com",
        "url": "https://github.com/WebAssembly/wabt/"
      },
      {
        "source": "cna@vuldb.com",
        "tags": [
          "Exploit",
          "Issue Tracking",
          "Vendor Advisory"
        ],
        "url": "https://github.com/WebAssembly/wabt/issues/2679"
      },
      {
        "source": "cna@vuldb.com",
        "tags": [
          "Exploit"
        ],
        "url": "https://github.com/oneafter/1208/blob/main/af1"
      },
      {
        "source": "cna@vuldb.com",
        "tags": [
          "Permissions Required",
          "VDB Entry"
        ],
        "url": "https://vuldb.com/?ctiid.339332"
      },
      {
        "source": "cna@vuldb.com",
        "tags": [
          "Third Party Advisory",
          "VDB Entry"
        ],
        "url": "https://vuldb.com/?id.339332"
      },
      {
        "source": "cna@vuldb.com",
        "tags": [
          "Third Party Advisory",
          "VDB Entry"
        ],
        "url": "https://vuldb.com/?submit.719825"
      },
      {
        "source": "cna@vuldb.com",
        "url": "https://vuldb.com/?submit.736404"
      }
    ],
    "sourceIdentifier": "cna@vuldb.com",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-119"
          }
        ],
        "source": "cna@vuldb.com",
        "type": "Secondary"
      }
    ]
  }
}
statusModified
receipt
Source
NVD
Its words
Modified
Read by
field:cve.vulnStatus
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-04 18:16 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "cpes": [
              "cpe:2.3:a:webassembly:wabt:*:*:*:*:*:*:*:*"
            ],
            "modules": [
              "wasm-decompile"
            ],
            "product": "wabt",
            "vendor": "WebAssembly",
            "versions": [
              {
                "status": "affected",
                "version": "1.0.0"
              },
              {
                "status": "affected",
                "version": "1.0.1"
              },
              {
                "status": "affected",
                "version": "1.0.2"
              },
              {
                "status": "affected",
                "version": "1.0.3"
              },
              {
                "status": "affected",
                "version": "1.0.4"
              },
              {
                "status": "affected",
                "version": "1.0.5"
              },
              {
                "status": "affected",
                "version": "1.0.6"
              },
              {
                "status": "affected",
                "version": "1.0.7"
              },
              {
                "status": "affected",
                "version": "1.0.8"
              },
              {
                "status": "affected",
                "version": "1.0.9"
              },
              {
                "status": "affected",
                "version": "1.0.10"
              },
              {
                "status": "affected",
                "version": "1.0.11"
              },
              {
                "status": "affected",
                "version": "1.0.12"
              },
              {
                "status": "affected",
                "version": "1.0.13"
              },
              {
                "status": "affected",
                "version": "1.0.14"
              },
              {
                "status": "affected",
                "version": "1.0.15"
              },
              {
                "status": "affected",
                "version": "1.0.16"
              },
              {
                "status": "affected",
                "version": "1.0.17"
              },
              {
                "status": "affected",
                "version": "1.0.18"
              },
              {
                "status": "affected",
                "version": "1.0.19"
              },
              {
                "status": "affected",
                "version": "1.0.20"
              },
              {
                "status": "affected",
                "version": "1.0.21"
              },
              {
                "status": "affected",
                "version": "1.0.22"
              },
              {
                "status": "affected",
                "version": "1.0.23"
              },
              {
                "status": "affected",
                "version": "1.0.24"
              },
              {
                "status": "affected",
                "version": "1.0.25"
              },
              {
                "status": "affected",
                "version": "1.0.26"
              },
              {
                "status": "affected",
                "version": "1.0.27"
              },
              {
                "status": "affected",
                "version": "1.0.28"
              },
              {
                "status": "affected",
                "version": "1.0.29"
              },
              {
                "status": "affected",
                "version": "1.0.30"
              },
              {
                "status": "affected",
                "version": "1.0.31"
              },
              {
                "status": "affected",
                "version": "1.0.32"
              },
              {
                "status": "affected",
                "version": "1.0.33"
              },
              {
                "status": "affected",
                "version": "1.0.34"
              },
              {
                "status": "affected",
                "version": "1.0.35"
              },
              {
                "status": "affected",
                "version": "1.0.36"
              },
              {
                "status": "affected",
                "version": "1.0.37"
              },
              {
                "status": "affected",
                "version": "1.0.38"
              },
              {
                "status": "affected",
                "version": "1.0.39"
              }
            ]
          }
        ],
        "source": "cna@vuldb.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:webassembly:wabt:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "4553C1EF-0407-4632-ACA5-3D1E2A76FBDA",
                "versionEndIncluding": "1.0.39",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A weakness has been identified in WebAssembly wabt up to 1.0.39. This vulnerability affects the function wabt::AST::InsertNode of the file /src/repro/wabt/bin/wasm-decompile of the component wasm-decompile. This manipulation causes memory corruption. It is possible to launch the attack on the local host. The exploit has been made available to the public and could be used for attacks. Unfortunately, the project has no active maintainer at the moment. In a reply to the issue report somebody recommended to the researcher to provide a PR himself."
      },
      {
        "lang": "es",
        "value": "Se ha identificado una debilidad en WebAssembly wabt hasta la versión 1.0.39. Esta vulnerabilidad afecta la función wabt::AST::InsertNode del archivo /src/repro/wabt/bin/wasm-decompile del componente wasm-decompile. Esta manipulación causa corrupción de memoria. Es posible lanzar el ataque en el host local. El exploit se ha puesto a disposición del público y podría usarse para ataques. Desafortunadamente, el proyecto no tiene ningún mantenedor activo en este momento. En una respuesta al informe del problema, alguien recomendó al investigador que proporcionara un PR él mismo."
      }
    ],
    "id": "CVE-2025-15411",
    "lastModified": "2026-10-01T08:10:00.183",
    "metrics": {
      "cvssMetricV2": [
        {
          "acInsufInfo": false,
          "baseSeverity": "MEDIUM",
          "cvssData": {
            "accessComplexity": "LOW",
            "accessVector": "LOCAL",
            "authentication": "SINGLE",
            "availabilityImpact": "PARTIAL",
            "baseScore": 4.3,
            "confidentialityImpact": "PARTIAL",
            "integrityImpact": "PARTIAL",
            "vectorString": "AV:L/AC:L/Au:S/C:P/I:P/A:P",
            "version": "2.0"
          },
          "exploitabilityScore": 3.1,
          "impactScore": 6.4,
          "obtainAllPrivilege": false,
          "obtainOtherPrivilege": false,
          "obtainUserPrivilege": false,
          "source": "cna@vuldb.com",
          "type": "Secondary",
          "userInteractionRequired": false
        }
      ],
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "LOW",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 3.4,
          "source": "cna@vuldb.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "LOCAL",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 1.9,
            "baseSeverity": "LOW",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "PROOF_OF_CONCEPT",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "LOW",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "LOW",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "cna@vuldb.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-15411",
            "options": [
              {
                "exploitation": "poc"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-01-05T21:03:24.165884Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-01-01T20:15:40.640",
    "references": [
      {
        "source": "cna@vuldb.com",
        "url": "https://github.com/WebAssembly/wabt/"
      },
      {
        "source": "cna@vuldb.com",
        "tags": [
          "Exploit",
          "Issue Tracking",
          "Vendor Advisory"
        ],
        "url": "https://github.com/WebAssembly/wabt/issues/2679"
      },
      {
        "source": "cna@vuldb.com",
        "tags": [
          "Exploit"
        ],
        "url": "https://github.com/oneafter/1208/blob/main/af1"
      },
      {
        "source": "cna@vuldb.com",
        "tags": [
          "Permissions Required",
          "VDB Entry"
        ],
        "url": "https://vuldb.com/?ctiid.339332"
      },
      {
        "source": "cna@vuldb.com",
        "tags": [
          "Third Party Advisory",
          "VDB Entry"
        ],
        "url": "https://vuldb.com/?id.339332"
      },
      {
        "source": "cna@vuldb.com",
        "tags": [
          "Third Party Advisory",
          "VDB Entry"
        ],
        "url": "https://vuldb.com/?submit.719825"
      },
      {
        "source": "cna@vuldb.com",
        "url": "https://vuldb.com/?submit.736404"
      }
    ],
    "sourceIdentifier": "cna@vuldb.com",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-119"
          }
        ],
        "source": "cna@vuldb.com",
        "type": "Secondary"
      }
    ]
  }
}
vendorWebAssembly
receipt
Source
NVD
Its words
WebAssembly
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-04 18:16 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "cpes": [
              "cpe:2.3:a:webassembly:wabt:*:*:*:*:*:*:*:*"
            ],
            "modules": [
              "wasm-decompile"
            ],
            "product": "wabt",
            "vendor": "WebAssembly",
            "versions": [
              {
                "status": "affected",
                "version": "1.0.0"
              },
              {
                "status": "affected",
                "version": "1.0.1"
              },
              {
                "status": "affected",
                "version": "1.0.2"
              },
              {
                "status": "affected",
                "version": "1.0.3"
              },
              {
                "status": "affected",
                "version": "1.0.4"
              },
              {
                "status": "affected",
                "version": "1.0.5"
              },
              {
                "status": "affected",
                "version": "1.0.6"
              },
              {
                "status": "affected",
                "version": "1.0.7"
              },
              {
                "status": "affected",
                "version": "1.0.8"
              },
              {
                "status": "affected",
                "version": "1.0.9"
              },
              {
                "status": "affected",
                "version": "1.0.10"
              },
              {
                "status": "affected",
                "version": "1.0.11"
              },
              {
                "status": "affected",
                "version": "1.0.12"
              },
              {
                "status": "affected",
                "version": "1.0.13"
              },
              {
                "status": "affected",
                "version": "1.0.14"
              },
              {
                "status": "affected",
                "version": "1.0.15"
              },
              {
                "status": "affected",
                "version": "1.0.16"
              },
              {
                "status": "affected",
                "version": "1.0.17"
              },
              {
                "status": "affected",
                "version": "1.0.18"
              },
              {
                "status": "affected",
                "version": "1.0.19"
              },
              {
                "status": "affected",
                "version": "1.0.20"
              },
              {
                "status": "affected",
                "version": "1.0.21"
              },
              {
                "status": "affected",
                "version": "1.0.22"
              },
              {
                "status": "affected",
                "version": "1.0.23"
              },
              {
                "status": "affected",
                "version": "1.0.24"
              },
              {
                "status": "affected",
                "version": "1.0.25"
              },
              {
                "status": "affected",
                "version": "1.0.26"
              },
              {
                "status": "affected",
                "version": "1.0.27"
              },
              {
                "status": "affected",
                "version": "1.0.28"
              },
              {
                "status": "affected",
                "version": "1.0.29"
              },
              {
                "status": "affected",
                "version": "1.0.30"
              },
              {
                "status": "affected",
                "version": "1.0.31"
              },
              {
                "status": "affected",
                "version": "1.0.32"
              },
              {
                "status": "affected",
                "version": "1.0.33"
              },
              {
                "status": "affected",
                "version": "1.0.34"
              },
              {
                "status": "affected",
                "version": "1.0.35"
              },
              {
                "status": "affected",
                "version": "1.0.36"
              },
              {
                "status": "affected",
                "version": "1.0.37"
              },
              {
                "status": "affected",
                "version": "1.0.38"
              },
              {
                "status": "affected",
                "version": "1.0.39"
              }
            ]
          }
        ],
        "source": "cna@vuldb.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:webassembly:wabt:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "4553C1EF-0407-4632-ACA5-3D1E2A76FBDA",
                "versionEndIncluding": "1.0.39",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A weakness has been identified in WebAssembly wabt up to 1.0.39. This vulnerability affects the function wabt::AST::InsertNode of the file /src/repro/wabt/bin/wasm-decompile of the component wasm-decompile. This manipulation causes memory corruption. It is possible to launch the attack on the local host. The exploit has been made available to the public and could be used for attacks. Unfortunately, the project has no active maintainer at the moment. In a reply to the issue report somebody recommended to the researcher to provide a PR himself."
      },
      {
        "lang": "es",
        "value": "Se ha identificado una debilidad en WebAssembly wabt hasta la versión 1.0.39. Esta vulnerabilidad afecta la función wabt::AST::InsertNode del archivo /src/repro/wabt/bin/wasm-decompile del componente wasm-decompile. Esta manipulación causa corrupción de memoria. Es posible lanzar el ataque en el host local. El exploit se ha puesto a disposición del público y podría usarse para ataques. Desafortunadamente, el proyecto no tiene ningún mantenedor activo en este momento. En una respuesta al informe del problema, alguien recomendó al investigador que proporcionara un PR él mismo."
      }
    ],
    "id": "CVE-2025-15411",
    "lastModified": "2026-10-01T08:10:00.183",
    "metrics": {
      "cvssMetricV2": [
        {
          "acInsufInfo": false,
          "baseSeverity": "MEDIUM",
          "cvssData": {
            "accessComplexity": "LOW",
            "accessVector": "LOCAL",
            "authentication": "SINGLE",
            "availabilityImpact": "PARTIAL",
            "baseScore": 4.3,
            "confidentialityImpact": "PARTIAL",
            "integrityImpact": "PARTIAL",
            "vectorString": "AV:L/AC:L/Au:S/C:P/I:P/A:P",
            "version": "2.0"
          },
          "exploitabilityScore": 3.1,
          "impactScore": 6.4,
          "obtainAllPrivilege": false,
          "obtainOtherPrivilege": false,
          "obtainUserPrivilege": false,
          "source": "cna@vuldb.com",
          "type": "Secondary",
          "userInteractionRequired": false
        }
      ],
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "LOW",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 3.4,
          "source": "cna@vuldb.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "LOCAL",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 1.9,
            "baseSeverity": "LOW",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "PROOF_OF_CONCEPT",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "LOW",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "LOW",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "cna@vuldb.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-15411",
            "options": [
              {
                "exploitation": "poc"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-01-05T21:03:24.165884Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-01-01T20:15:40.640",
    "references": [
      {
        "source": "cna@vuldb.com",
        "url": "https://github.com/WebAssembly/wabt/"
      },
      {
        "source": "cna@vuldb.com",
        "tags": [
          "Exploit",
          "Issue Tracking",
          "Vendor Advisory"
        ],
        "url": "https://github.com/WebAssembly/wabt/issues/2679"
      },
      {
        "source": "cna@vuldb.com",
        "tags": [
          "Exploit"
        ],
        "url": "https://github.com/oneafter/1208/blob/main/af1"
      },
      {
        "source": "cna@vuldb.com",
        "tags": [
          "Permissions Required",
          "VDB Entry"
        ],
        "url": "https://vuldb.com/?ctiid.339332"
      },
      {
        "source": "cna@vuldb.com",
        "tags": [
          "Third Party Advisory",
          "VDB Entry"
        ],
        "url": "https://vuldb.com/?id.339332"
      },
      {
        "source": "cna@vuldb.com",
        "tags": [
          "Third Party Advisory",
          "VDB Entry"
        ],
        "url": "https://vuldb.com/?submit.719825"
      },
      {
        "source": "cna@vuldb.com",
        "url": "https://vuldb.com/?submit.736404"
      }
    ],
    "sourceIdentifier": "cna@vuldb.com",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-119"
          }
        ],
        "source": "cna@vuldb.com",
        "type": "Secondary"
      }
    ]
  }
}

Text

A weakness has been identified in WebAssembly wabt up to 1.0.39. This vulnerability affects the function wabt::AST::InsertNode of the file /src/repro/wabt/bin/wasm-decompile of the component wasm-decompile. This manipulation causes memory corruption. It is possible to launch the attack on the local host. The exploit has been made available to the public and could be used for attacks. Unfortunately, the project has no active maintainer at the moment. In a reply to the issue report somebody recommended to the researcher to provide a PR himself. Se ha identificado una debilidad en WebAssembly wabt hasta la versión 1.0.39. Esta vulnerabilidad afecta la función wabt::AST::InsertNode del archivo /src/repro/wabt/bin/wasm-decompile del componente wasm-decompile. Esta manipulación causa corrupción de memoria. Es posible lanzar el ataque en el host local. El exploit se ha puesto a disposición del público y podría usarse para ataques. Desafortunadamente, el proyecto no tiene ningún mantenedor activo en este momento. En una respuesta al informe del problema, alguien recomendó al investigador que proporcionara un PR él mismo.