Tools AI-Found Vulnerability Register aifv-0010
Register entry
QuickJS js_std_promise_rejection_check: use-after-free, found by Google Big Sleep
- CVE
- CVE-2025-62491
- Project
- QuickJS
- Component
- js_std_promise_rejection_check
- Finder
- Google Big Sleep
- Autonomy
- agent finds and reproduces; a human expert reviews before reporting
- Evidence tier
- Credits array names the finder
- Assigner
- Severity
- 8.8 High (CVSS 4.0)
- Bounty
- None published
- Confidence
- CONFIRMED
What happened
One of seven QuickJS records Google filed as CNA on 16 October 2025 with Big Sleep as finder, all sharing a datePublic of 24 July 2025 and affecting QuickJS 2025-04-26 up to 2025-09-13.
Credit as recorded: finder: "Google Big Sleep". Date basis: datePublic.
Sources
- CVE record, cvelistV5 mirrorraw.githubusercontent.com/CVEProject/cvelistV5/main/cves/202…
On YFarmX
- Reference pageyfarmx.com/ai/security/big-sleep/
One record from the AI-Found Vulnerability Register, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 19 September 2026