wasmtime-wasi is vulnerable to Improper Access Control
75
High Risk
Affected versions of wasmtime-wasi are vulnerable to an access control bypass in filesystem preopen permission handling. A guest application can use file truncation flags with read-only file permissions to modify files despite missing write permissions, bypassing intended FilePerms restrictions in certain DirPerms::MUTATE configurations.
You are affected if you are using a version that falls within the vulnerable range.
wasmtime-wasi is vulnerable to Improper Access Control in versions 0.0.1 - 24.0.8, 25.0.0 - 36.0.9 and 37.0.0 - 44.0.1.
Upgrade the wasmtime-wasi library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant