CVE-2025-15411 | WebAssembly wabt up to 1.0.39 wasm-decompile wabt::AST::InsertNode memory corruption (Issue 2679 / EUVD-2026-0006)
A vulnerability classified as critical has been found in WebAssembly wabt up to 1.0.39. This vulnerability affects the function wabt::AST::InsertNode of the file /src/repro/wabt/bin/wasm-decompile of the component wasm-decompile. This manipulation causes memory corruption.
This vulnerability is handled as CVE-2025-15411. It is possible to launch the attack on the local host. Additionally, an exploit exists.
Unfortunately, the project has no active maintainer at the moment. In a reply to the issue report somebody recommended to the researcher to provide a PR himself.