PT-2026-98152 · Git · Espruino
CVE-2026-88390
·
Published
2026-09-24
·
Updated
2026-09-24
CVSS v3.1
7.7
High
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Espruino version 2v29
Description
An out-of-bounds write occurs in the
jslGetTokenValueAsString() function when processing crafted JavaScript input containing an overlong token. In RELEASE/NO ASSERT builds, this triggers a one-byte write beyond the JsLex.token buffer, which corrupts the adjacent tokenValue pointer. This memory corruption can lead to application crashes or denial of service.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Espruino