CVE-2023-48184

Severity CVSS v4.0:
Pending analysis
Type:
CWE-416 Use After Free
Publication date:
23/04/2024
Last modified:
15/10/2025

Description

QuickJS before 7414e5f has a quickjs.h JS_FreeValueRT use-after-free because of incorrect garbage collection of async functions with closures.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:quickjs_project:quickjs:*:*:*:*:*:*:*:* 2023-12-27 (excluding)