YFarmX logoYFarmX

Tools AI-Found Vulnerability Register aifv-0014

Register entry

QuickJS libregexp: bytecode size integer overflow, found by Google Big Sleep

CVE
CVE-2025-62495
Project
QuickJS
Component
libregexp
Finder
Google Big Sleep
Autonomy
agent finds and reproduces; a human expert reviews before reporting
Evidence tier
Credits array names the finder
Assigner
Google
Severity
7.1 High (CVSS 4.0)
Bounty
None published
Confidence
CONFIRMED

What happened

One of seven QuickJS records Google filed as CNA on 16 October 2025 with Big Sleep as finder, all sharing a datePublic of 24 July 2025 and affecting QuickJS 2025-04-26 up to 2025-09-13.

Credit as recorded: finder: "Google Big Sleep". The record title duplicates CVE-2025-62494, "Type confusion in string addition in QuickJS", while its description is the libregexp bytecode integer overflow; the description is right and the upstream title is the duplicate. Date basis: datePublic.

Sources

One record from the AI-Found Vulnerability Register, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 19 September 2026