Bellard maintains QuickJS, a JavaScript engine and interpreter whose vulnerability profile clusters around resource-management and memory-access weaknesses such as unbounded resource allocation, buffer over-reads, and out-of-bounds reads. These issues reflect the parsing and runtime demands of a dynamically typed language implementation; defenders integrating this engine should monitor releases and consider deployment constraints on untrusted scripts. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bellard over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-12745HIGH A weakness has been identified in QuickJS up to eb2c89087def1829ed99630cb14b549d7a98408c. This affects the function js_array_buffer_slice of the file quickjs.c. This manipulation c | Nov 5, 2025 | 7.8 | 25 | NO | NO |
CVE-2025-46687HIGH quickjs-ng through 0.9.0 has a missing length check in JS_ReadString for a string, leading to a heap-based buffer overflow. QuickJS before 2025-04-26 is also affected. | Apr 27, 2025 | 7.8 | 22 | NO | NO |
CVE-2024-33263MEDIUM QuickJS commit 3b45d15 was discovered to contain an Assertion Failure via JS_FreeRuntime(JSRuntime *) at quickjs.c. | May 14, 2024 | 4.0 | 14 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bellard.
Media articles that mention a CVE ID that affects a product developed by Bellard — matched by CVE ID, not by vendor name.