PT-2026-95591 · Npm · Uri.Js

·

CVE-2026-93751

·

Published

2026-09-18

·

Updated

2026-09-27

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions uri-js versions 4.4.1 and earlier
Description An improper UTF-8 decoding issue exists in the pctDecChars() function. This flaw allows the decoding of invalid and overlong percent-encoded sequences into ASCII metacharacters. Attackers can use crafted percent-encoded payloads to bypass platform decoder validation, enabling the injection of path traversal or CRLF (Carriage Return Line Feed) sequences that may be processed without filtering by downstream consumers.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-103436
CVE-2026-93751

Affected Products

Uri.Js