CVE-2026-37630

high
Published 2026-05-11 · Modified 2026-05-13
CVSS v3
7.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CVSS v4 NEW
not yet in upstream
VIR risk
7.3

Description

An issue in QuickJS-NG v.0.12.1 allows an attacker to execute arbitrary code via the js_mapped_arguments_mark function

Predictions

Exploit likelihood
82%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker · View original ↗ · DFSG

CVE-2026-37630 NameCVE-2026-37630 DescriptionAn issue in QuickJS-NG v.0.12.1 allows an attacker to execute arbitrary code via the js_mapped_arguments_mark function SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) Vulnerable and fixed packages The table below lists information on source…

CVE-2026-37630

NameCVE-2026-37630
DescriptionAn issue in QuickJS-NG v.0.12.1 allows an attacker to execute arbitrary code via the js_mapped_arguments_mark function
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
quickjs-ng (PTS)forky, sid0.15.0-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
quickjs-ngsource(unstable)(not affected)

Notes

- quickjs-ng <not-affected> (Fixed with initial upload to Debian)
https://github.com/quickjs-ng/quickjs/issues/1400
https://github.com/quickjs-ng/quickjs/pull/1401
Fixed by: https://github.com/quickjs-ng/quickjs/commit/397310610529adee8b6d763f7cbe3cb3d2fbaa09 (v0.13.0)

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
- quickjs-ng <not-affected> (Fixed with initial upload to Debian)https://github.com/quickjs-ng/quickjs/issues/1400https://github.com/quickjs-ng/quickjs/pull/1401Fixed by: https://github.com/quickjs-ng/quickjs/commit/397310610529adee8b6d763f7cbe3cb3d2fbaa09 (v0.13.0)

OS impact

debian Debian Fixed 2 releases
VersionStatusFixed in
sid Fixed 0
forky Fixed 0

References

CWEs

CWE-94

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.