PatchSiren cyber security CVE debrief
CVE-2026-58494 bytecodealliance CVE debrief
A vulnerability in Wasmtime, a runtime for WebAssembly, allows a WASI guest with read-only source file capability to overwrite host files. This issue arises from wasmtime-wasi's hard-link creation and renaming checks not properly verifying FilePerms on source and destination preopens. The vulnerability is fixed in versions 24.0.11, 36.0.12, 45.0.3, and 46.0.1. Defenders of systems using Wasmtime should prioritize patching to prevent potential file system manipulation.
- Vendor
- bytecodealliance
- Product
- wasmtime
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-08
- Original CVE updated
- 2026-07-10
- Advisory published
- 2026-07-08
- Advisory updated
- 2026-07-10
Who should care
Defenders of systems using Wasmtime should prioritize patching to prevent potential file system manipulation. This includes operators managing Wasmtime deployments, platform administrators, vulnerability management teams, and security teams responsible for monitoring and incident response.
Technical summary
The vulnerability, CVE-2026-58494, arises from wasmtime-wasi's hard-link creation and renaming checks not properly verifying FilePerms on source and destination preopens. This oversight enables a WASI guest to bypass intended file system restrictions, potentially leading to unauthorized file overwrites on the host system. The issue is addressed in Wasmtime versions 24.0.11, 36.0.12, 45.0.3, and 46.0.1 through improved permission checks.
Defensive priority
Medium priority due to the potential for file system manipulation and the availability of patches.
Recommended defensive actions
- Apply patches (versions 24.0.11, 36.0.12, 45.0.3, 46.0.1) to Wasmtime installations.
- Review and restrict WASI guest capabilities, especially those involving file system interactions.
- Monitor for unusual file system activities that could indicate exploitation attempts.
- Conduct a thorough review of current Wasmtime deployments to identify potential exposure.
- Inventory assets that may be impacted and prioritize patching based on criticality.
- Implement compensating controls such as enhanced monitoring and access restrictions for high-risk systems.
Evidence notes
The CVE record and NVD detail provide official information on the vulnerability. GitHub commits and release tags offer technical details on the fixes. Evidence is limited to public sources and may not cover all affected systems or potential impacts. Defenders should verify system exposure and review vendor guidance for specific patching and mitigation steps.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-58494 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-58494
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-58494 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-58494
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/bytecodealliance/wasmtime/commit/5ddfd5f1ef28f2041fa07d237ad0336e167b0e0c
-
Source reference
Unverified legacy reference
URL: https://github.com/bytecodealliance/wasmtime/commit/7db94cdcf0c79cb3dfde884b534b653f2dd83367
-
Source reference
Unverified legacy reference
URL: https://github.com/bytecodealliance/wasmtime/commit/8a250aac0962ca1364b5f16525720e9d0b39edcd
-
Source reference
Unverified legacy reference
URL: https://github.com/bytecodealliance/wasmtime/commit/d3ceb56ec35f39e02496eeb4e2d9c7f4fb964d9e
-
Source reference
Unverified legacy reference
URL: https://github.com/bytecodealliance/wasmtime/releases/tag/v24.0.11
-
Source reference
Unverified legacy reference
URL: https://github.com/bytecodealliance/wasmtime/releases/tag/v36.0.12
-
Source reference
Unverified legacy reference
URL: https://github.com/bytecodealliance/wasmtime/releases/tag/v45.0.3
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.