Multiple vulnerabilities have been found in quickjs-ng, the worst of which could result in arbitrary code execution.
| Package | dev-libs/quickjs-ng on all architectures |
|---|---|
| Affected versions | < 0.12.0 |
| Unaffected versions | >= 0.12.0 |
quickjs-ng is a small and embeddable JavaScript engine. It aims to support the latest ECMAScript specification. It is a fork of QuickJS.
Multiple vulnerabilities have been discovered in quickjs-ng. Please review the CVE identifiers referenced below for details.
Please review the referenced CVE identifiers for details.
There is no known workaround at this time.
All quickjs-ng users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose ">=dev-libs/quickjs-ng-0.12.0"
Release date
August 20, 2026
Latest revision
August 20, 2026: 1
Severity
high
Exploitable
remote
Bugzilla entries