CVE-2026-37630: Code Injection
Published May 11, 2026
·Updated
An issue in QuickJS-NG v.0.12.1 allows an attacker to execute arbitrary code via the jsmappedargumentsmark function
Affected Software
1 affected component
quickjs-ng QuickJS-NG=0.12.1
Event History
May 11, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:18 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-37630?
CVE-2026-37630 has been classified as a critical severity vulnerability due to its potential to allow arbitrary code execution.
2
How do I fix CVE-2026-37630?
The recommended fix for CVE-2026-37630 is to upgrade QuickJS-NG to version 0.12.2 or later, where the vulnerability has been addressed.
3
What software is affected by CVE-2026-37630?
CVE-2026-37630 affects QuickJS-NG version 0.12.1.
4
Can CVE-2026-37630 be exploited remotely?
Yes, an attacker can exploit CVE-2026-37630 remotely to execute arbitrary code.
5
What is the impact of CVE-2026-37630 on systems using QuickJS-NG?
The impact of CVE-2026-37630 includes the potential for unauthorized access and control over compromised systems, leading to data loss or integrity issues.