We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-47154



Description

LibJS in Ladybird before f5a6704 mishandles the freeing of the vector that arguments_list references, leading to a use-after-free, and allowing remote attackers to execute arbitrary code via a crafted .js file. NOTE: the GitHub README says "Ladybird is in a pre-alpha state, and only suitable for use by developers."

Reserved 2025-05-01 | Published 2025-05-01 | Updated 2025-05-01 | Assigner mitre


CRITICAL: 9.0CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Problem types

CWE-820 Missing Synchronization

Product status

Default status
unaffected

Any version before f5a670421954fc7130c3685b713c621b29516669
affected

References

news.ycombinator.com/item?id=43852096

jessie.cafe/posts/pwning-ladybirds-libjs/

github.com/...ommit/f5a670421954fc7130c3685b713c621b29516669

cve.org (CVE-2025-47154)

nvd.nist.gov (CVE-2025-47154)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-47154

Support options

Helpdesk Chat, Email, Knowledgebase