GHSA-4mq4-7rw3-vm5j

    Dashboard / Vulnerabilities / GHSA-4mq4-7rw3-vm5j

    GHSA-4mq4-7rw3-vm5j

    Published: 13 Dec 2023Last Modified: 10 Sept 2026

    Summary: Wasmer filesystem sandbox not enforced

    Details: ### Summary As of Wasmer version v4.2.3, Wasm programs can access the filesystem outside of the sandbox. ### Details https://github.com/wasmerio/wasmer/issues/4267 ### PoC A minimal Rust program: ``` fn main() { let f = std::fs::OpenOptions::new() .write(true) .create_new(true) .open("abc") .unwrap(); } ``` This should be compiled with `cargo build --target wasm32-wasi`. The compiled program, when run with wasmer WITHOUT `--dir`, can still create a file in the working directory. ### Impact Service providers running untrusted Wasm code on Wasmer can unexpectedly expose the host filesystem.

    Affected packages

    Package

    Name: wasmer-cli

    Purl: pkg:cargo/wasmer-cli

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 3.0.0
    Fixed -4.2.4

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-4mq4-7rw3-vm5j | CVE-DB