← back
CVE-2026-3979

quickjs-ng quickjs quickjs.c js_iterator_concat_return use after free

CVSS 4.8 MEDIUMEPSS 0.1%CWE-119CWE-416
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 4.8EPSS 0.1%KEV nãoPoC Nuclei Metasploit Patch referenciado
Lifecycle
12 Mar 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A flaw has been found in quickjs-ng quickjs up to 0.12.1. This affects the function js_iterator_concat_return of the file quickjs.c. This manipulation causes use after free. The attack requires local access. The exploit has been published and may be used. Patch name: daab4ad4bae4ef071ed0294618d6244e92def4cd. Applying a patch is the recommended action to fix this issue.
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Affected products
quickjs-ng · quickjs