CVE-2024-13903

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Mar 21, 2025
Updated: Mar 24, 2025
CWE ID 119
CWE ID 787
CWE ID 121

Summary

CVE-2024-13903 is a newly discovered vulnerability affecting quickjs-ng QuickJS versions up to 0.8.0. This issue, which has been classified as problematic, is located in the JS_GetRuntime function of quickjs.c within the qjs component. A successful exploit leads to a stack-based buffer overflow, making it remotely exploitable. Upgrading to QuickJS version 0.9.0 is the advised solution, as it incorporates the necessary patch (99c02eb45170775a9a679c32b45dd4000ea67aff). It is strongly recommended to upgrade the affected component without delay to mitigate potential risks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share