wasmtime is vulnerable to Path Traversal
88
High Risk
The filesystem sandbox resolves guest paths and symlinks incorrectly when they contain trailing slashes, letting the resolution escape the preopened directory. A guest with filesystem access can read and write files and directories outside its sandbox, up to what the host process itself can reach. Exposure is on macOS, Windows, and Linux where openat2 RESOLVE_BENEATH is unavailable (kernel older than 5.6, or openat2 blocked). The fix corrects trailing-slash path resolution so sandboxed lookups stay confined to the granted directory.
You are affected if you are using a version that falls within the vulnerable range and you grant guest code filesystem access on macOS, Windows, or Linux where openat2 RESOLVE_BENEATH is unavailable (kernel older than 5.6, or openat2 blocked).
wasmtime is vulnerable to Path Traversal in versions 0.0.1 - 24.0.12, 25.0.0 - 36.0.13, 37.0.0 - 46.0.2 and 47.0.0 - 47.0.3.
Upgrade the wasmtime library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant