QuickJS是QuickJS开源的一个小型且可嵌入的 Javascript 引擎。 QuickJS存在安全漏洞,该漏洞源于js_print_object函数在打印数组和集合对象时未正确处理回调期间的数组大小变化,可能导致释放后重用。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-62492 | Heap out-of-bounds read in js_typed_array_indexOf in QuickJS | |
| CVE-2025-62493 | Heap out-of-bounds read in js_bigint_to_string1 in QuickJS | |
| CVE-2025-62494 | Type confusion in string addition in QuickJS | |
| CVE-2025-62495 | Type confusion in string addition in QuickJS | |
| CVE-2025-62491 | Use-after-free in js_std_promise_rejection_check in QuickJS | |
| CVE-2025-62496 | Integer overflow in js_bigint_from_string in QuickJS |
No comments yet