Multiple vulnerabilities have been found in quickjs-ng, the worst of which could result in arbitrary code execution. Affected packages Package dev-libs/quickjs-ng on all architectures Affected versions < 0.12.0 Unaffected versions >= 0.12.0 Background quickjs-ng is a small and embeddable JavaScript engine. It aims to support the latest ECMAScript specification. It is a fork of QuickJS. Description Multiple vulnerabilities have been discovered in quickjs-ng. Please review the CVE identifiers referenced below for details. Impact Please review the referenced CVE identifiers for details. Workaround There is no known workaround at this time. Resolution All quickjs-ng users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=dev-libs/quickjs-ng-0.12.0" References CVE-2026-0821 CVE-2026-1144 CVE-2026-1145 Release date August 20, 2026 Latest revision August 20, 2026: 1 Severity high Exploitable remote Bugzilla entries 969863
Multiple vulnerabilities in quickjs-ng, including a high-severity flaw (CVE-2026-0821, CVSS 7.3) that could lead to arbitrary code execution, affect versions up to and including 0.11.0. The resolution is to upgrade to version 0.12.0 or later, as there is no known workaround.