Intel

AIKIDO-2026-10926

wasmtime-wasi is vulnerable to Improper Access Control

Improper Access ControlCVE-2026-47261 Published 2 days ago

75

High Risk

This Affects:

RUSTwasmtime-wasi
0.0.1 - 24.0.8
Fixed in 24.0.9
25.0.0 - 36.0.9
Fixed in 36.0.10
37.0.0 - 44.0.1
Fixed in 44.0.2
Are you affected? Scan for Free

TL;DR

Affected versions of wasmtime-wasi are vulnerable to an access control bypass in filesystem preopen permission handling. A guest application can use file truncation flags with read-only file permissions to modify files despite missing write permissions, bypassing intended FilePerms restrictions in certain DirPerms::MUTATE configurations.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

wasmtime-wasi is vulnerable to Improper Access Control in versions 0.0.1 - 24.0.8, 25.0.0 - 36.0.9 and 37.0.0 - 44.0.1.

How to fix this

Upgrade the wasmtime-wasi library to the patch version.