---
id: CVE-2026-58494
aliases:
  - RUSTSEC-2026-0188
  - GHSA-4ch3-9j33-3pmj
title: WASI hard links and renames bypass wasmtime-wasi's FilePerms for destination
summary: WASI hard links and renames bypass wasmtime-wasi's FilePerms for destination
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N'
vendor: wasmtime-wasi
product: wasmtime-wasi
ecosystem: rust
affected:
  - 'wasmtime-wasi >= 46.0.0, < 46.0.1'
patched:
  - wasmtime-wasi 46.0.1
published: '2026-06-24'
updated: '2026-07-10'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/RUSTSEC-2026-0188'
references:
  - url: 'https://crates.io/crates/wasmtime-wasi'
  - url: 'https://rustsec.org/advisories/RUSTSEC-2026-0188.html'
  - url: >-
      https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-4ch3-9j33-3pmj
tags:
  - osv
  - rust
epss: 0.00171
epssPercentile: 0.05696
ingestedAt: '2026-07-10T18:56:50.820Z'
---

## Overview

This is an entry in the RustSec database for the Wasmtime security advisory
located at
https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-4ch3-9j33-3pmj
For more information see the GitHub-hosted security advisory.

## Affected packages

- `wasmtime-wasi >= 46.0.0, < 46.0.1`

## Remediation

Upgrade to a patched release:

- `wasmtime-wasi 46.0.1`
