← Vulnerability feed

Vulnerability record · CVE-2025-43853 · published 15 May 2025

CVE-2025-43853: Bytecodealliance webassembly micro runtime vulnerability

Bytecodealliance · Webassembly Micro Runtime

The WebAssembly Micro Runtime's (WAMR) iwasm package is the executable binary built with WAMR VMcore which supports WebAssembly System Interface (WASI) and command line interface. Anyone running WAMR up to and including version 2.2.0 or WAMR built with libc-uvwasi on Windows is affected by a symlink following vulnerability. On WAMR running in Windows, creating a symlink pointing outside of the preopened directory and subsequently opening it with create flag will create a file on host outside of the sandbox. If the symlink points to an existing host file, it's also possible to open it and read its content. Version 2.3.0 fixes the issue.

7.0 CVSS 4.0 High EPSS 0.28% · top 81.6% CWE-61 · CWE-61
7.0CVSS 4.0 base score
0.28%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

The WebAssembly Micro Runtime's (WAMR) iwasm package is the executable binary built with WAMR VMcore which supports WebAssembly System Interface (WASI) and command line interface. Anyone running WAMR up to and including version 2.2.0 or WAMR built with libc-uvwasi on Windows is affected by a symlink following vulnerability. On WAMR running in Windows, creating a symlink pointing outside of the preopened directory and subsequently opening it with create flag will create a file on host outside of the sandbox. If the symlink points to an existing host file, it's also possible to open it and read its content. Version 2.3.0 fixes the issue.

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-43853 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2024-25431Bytecodealliance webassembly micro runtime out-of-bounds read vulnerabilityAn issue in bytecodealliance wasm-micro-runtime before v.b3f728c and fixed in commit 06df58f allows a remote attacker to escalate privileges via a cr…EPSS 0.63%7.5CVE-2024-27532Bytecodealliance webassembly micro runtime null pointer dereference vulnerabilitywasm-micro-runtime (aka WebAssembly Micro Runtime or WAMR) 06df58f is vulnerable to NULL Pointer Dereference in function `block_type_get_result_types.EPSS 0.51%7.5CVE-2024-34251Bytecodealliance webassembly micro runtime out-of-bounds read vulnerabilityAn out-of-bound memory read vulnerability was discovered in Bytecode Alliance wasm-micro-runtime v2.0.0 which allows a remote attacker to cause a den…EPSS 0.76%7.5CVE-2023-48105Bytecodealliance webassembly micro runtime out-of-bounds write vulnerabilityAn heap overflow vulnerability was discovered in Bytecode alliance wasm-micro-runtime v.1.2.3 allows a remote attacker to cause a denial of service v…EPSS 1.0%7.4CVE-2025-64713Bytecodealliance webassembly micro runtime memory buffer overflow vulnerabilityWebAssembly Micro Runtime (WAMR) is a lightweight standalone WebAssembly (Wasm) runtime. Prior to version 2.4.4, an out-of-bounds array access issue …EPSS 0.33%6.9CVE-2025-54126Bytecodealliance webassembly micro runtime exposure of resource to wrong sphere vulnerabilityThe WebAssembly Micro Runtime's (WAMR) iwasm package is the executable binary built with WAMR VMcore which supports WebAssembly System Interface (WAS…EPSS 0.63%6.2CVE-2024-34250Bytecodealliance webassembly micro runtime heap-based buffer overflow vulnerabilityA heap buffer overflow vulnerability was discovered in Bytecode Alliance wasm-micro-runtime v2.0.0 which allows a remote attacker to cause at least a…EPSS 0.33%5.5CVE-2025-64704Bytecodealliance webassembly micro runtime vulnerabilityWebAssembly Micro Runtime (WAMR) is a lightweight standalone WebAssembly (Wasm) runtime. Prior to version 2.4.4, WAMR is susceptible to a segmentatio…EPSS 0.19%

Source: NIST National Vulnerability Database (record CVE-2025-43853), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.