affected: - ecosystem_specific: {} package: ecosystem: PyPI name: pywasm3 purl: pkg:pypi/pywasm3 ranges: - events: - introduced: '0' - last_affected: 0.5.0 type: ECOSYSTEM versions: - 0.0.1 - 0.0.2 - 0.4.8 - 0.4.9 - 0.5.0 aliases: - CVE-2025-6272 - GHSA-rrmw-gv85-w824 details: A vulnerability has been found in wasm3 0.5.0 and classified as problematic. This vulnerability affects the function MarkSlotAllocated of the file source/m3_compile.c. The manipulation leads to out-of-bounds write. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. id: PYSEC-2025-186 modified: '2026-05-21T14:54:42.578466Z' published: '2025-06-19T18:15:22Z' references: - type: ADVISORY url: https://vuldb.com/?id.313276 - type: ADVISORY url: https://vuldb.com/?submit.593008 - type: REPORT url: https://github.com/wasm3/wasm3/issues/531 - type: REPORT url: https://vuldb.com/?ctiid.313276 - type: EVIDENCE url: https://github.com/user-attachments/files/19516600/wasm3_crash.txt - type: ADVISORY url: https://github.com/advisories/GHSA-rrmw-gv85-w824 severity: - score: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X type: CVSS_V4