{"id":"CVE-2026-88390","published":"2026-09-24T17:17:08.143","lastModified":"2026-09-24T21:08:55.030","description":"An out-of-bounds write vulnerability in jslGetTokenValueAsString() in Espruino 2v29 (commit bffc6d0) allows crafted JavaScript input containing an overlong token to trigger a one-byte write beyond the JsLex.token buffer in RELEASE/NO_ASSERT builds. The out-of-bounds write corrupts the adjacent tokenValue pointer, resulting in memory corruption and potentially causing application crashes or denial of service.","cvssScore":7.7,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","cwes":["CWE-787"],"vendors":[],"products":[],"references":[{"url":"https://github.com/espruino/Espruino/commit/ecd7d43e084ba9aafa8245609347fe0f4383b38c","tags":[]},{"url":"https://github.com/espruino/Espruino/issues/2744","tags":[]},{"url":"https://github.com/espruino/Espruino/issues/2744","tags":[]}],"exploitRefs":[{"url":"https://github.com/espruino/Espruino/commit/ecd7d43e084ba9aafa8245609347fe0f4383b38c","tags":[]},{"url":"https://github.com/espruino/Espruino/issues/2744","tags":[]},{"url":"https://github.com/espruino/Espruino/issues/2744","tags":[]}],"hasPoc":true,"ai":null}