Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 24 Sep 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Espruino
Espruino espruino |
|
| Vendors & Products |
Espruino
Espruino espruino |
Thu, 24 Sep 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-787 | |
| Metrics |
cvssV3_1
|
Thu, 24 Sep 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An out-of-bounds write vulnerability in jslGetTokenValueAsString() in Espruino 2v29 (commit bffc6d0) allows crafted JavaScript input containing an overlong token to trigger a one-byte write beyond the JsLex.token buffer in RELEASE/NO_ASSERT builds. The out-of-bounds write corrupts the adjacent tokenValue pointer, resulting in memory corruption and potentially causing application crashes or denial of service. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-09-24T18:59:33.570Z
Reserved: 2026-09-10T00:00:00.000Z
Link: CVE-2026-88390
Updated: 2026-09-24T18:57:41.098Z
Status : Received
Published: 2026-09-24T17:17:08.143
Modified: 2026-09-24T19:17:19.407
Link: CVE-2026-88390
No data.
OpenCVE Enrichment
Updated: 2026-09-24T19:30:17Z
-
CWE-787
Out-of-bounds Write