CVE-2025-69654 describes a denial-of-service vulnerability in QuickJS release 2025-09-13. A specially crafted JavaScript input, when executed with the -m option and a low memory limit, can trigger an out-of-memory condition followed by an assertion failure during runtime cleanup, leading to a SIGABRT. This issue was resolved in commit fcd33c1afa7b3028531f53cd1190a3877454f6b3. The vulnerability has a FAUCET Risk Score of 20/100, indicating a relatively low severity. The attack vector involves providing malicious JavaScript input, but the complexity is moderate as it requires specific execution parameters. The primary impact is denial of service due to the application crashing. There is no evidence of active exploitation, and no exploit code is publicly available through Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are minimal, which is typical for the majority of CVEs.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2025-09-13, < 2025-12-11CPE matchmatch criteria | cpe:2.3:a:quickjs_project:quickjs:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.