/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-w9fv-xx2g-xxgm

Published

Last updated

https://images.chainguard.dev/security/CGA-w9fv-xx2g-xxgm
Package

zed

RepositoryWolfi
Latest Update
Pending upstream fix
Aliases
  • CVE-2025-64345
  • GHSA-hc7m-r6v8-hg9q

Severity

1.8

Low

CVSS V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-64345

Updates

Status

Pending upstream fix

Impact

The wasmtime version is explicitly pinned upstream[1] and the maintainers have raised concerns at previous efforts to bump the version[2]. Upstream maintainers will need to update the version of wasmtime to ensure it remains compatible with tree-sitter. [1] https://github.com/zed-industries/zed/blob/6bf5e92a25e6bb87dfdecc861b5a94c4a6a632c9/Cargo.toml#L711 [2] https://github.com/zed-industries/zed/pull/38819#issuecomment-3334589640

Status

Under investigation


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing