CVE-2025-15412 | WebAssembly wabt up to 1.0.39 wasm-decompile VarName out-of-bounds (Issue 2678 / EUVD-2026-0003)
A vulnerability classified as critical was found in WebAssembly wabt up to 1.0.39. This issue affects the function wabt::Decompiler::VarName of the file /src/repro/wabt/bin/wasm-decompile of the component wasm-decompile. Such manipulation leads to out-of-bounds read.
This vulnerability is uniquely identified as CVE-2025-15412. Local access is required to approach this attack. Moreover, an exploit is present.
Unfortunately, the project has no active maintainer at the moment. In a reply to the issue report somebody recommended to the researcher to provide a PR himself.