CVE-2025-15412

A security vulnerability has been detected in WebAssembly wabt up to 1.0.39. This issue affects the function wabt::Decompiler::VarName of the file /src/repro/wabt/bin/wasm-decompile of the component wasm-decompile. Such manipulation leads to out-of-bounds read. Local access is required to approach this attack. The exploit has been disclosed publicly and may be used. Unfortunately, the project has no active maintainer at the moment. In a reply to the issue report somebody recommended to the researcher to provide a PR himself.
References
Link Resource
https://github.com/WebAssembly/wabt/issues/2678 Exploit Issue Tracking Vendor Advisory
https://github.com/oneafter/1208/blob/main/af1 Exploit
https://vuldb.com/?ctiid.339333 Permissions Required VDB Entry
https://vuldb.com/?id.339333 Third Party Advisory VDB Entry
https://vuldb.com/?submit.719826 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:webassembly:wabt:*:*:*:*:*:*:*:*

History

06 Jan 2026, 15:36

Type Values Removed Values Added
References () https://github.com/WebAssembly/wabt/issues/2678 - () https://github.com/WebAssembly/wabt/issues/2678 - Exploit, Issue Tracking, Vendor Advisory
References () https://github.com/oneafter/1208/blob/main/af1 - () https://github.com/oneafter/1208/blob/main/af1 - Exploit
References () https://vuldb.com/?ctiid.339333 - () https://vuldb.com/?ctiid.339333 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.339333 - () https://vuldb.com/?id.339333 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.719826 - () https://vuldb.com/?submit.719826 - Third Party Advisory, VDB Entry
CPE cpe:2.3:a:webassembly:wabt:*:*:*:*:*:*:*:*
First Time Webassembly
Webassembly wabt

01 Jan 2026, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-01 21:15

Updated : 2026-01-06 15:36


NVD link : CVE-2025-15412

Mitre link : CVE-2025-15412

CVE.ORG link : CVE-2025-15412


JSON object : View

Products Affected

webassembly

  • wabt
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-125

Out-of-bounds Read