{"id":"CVE-2026-88388","title":"Espruino 2v29 (commit bffc6d0) contains a stack-based buffer overflow vulnerability in the JavaScript error stack-trace handling path on 64-bit builds","summary":"Espruino 2v29 (commit bffc6d0) contains a stack-based buffer overflow vulnerability in the JavaScript error stack-trace handling path on 64-bit builds. A remote attacker can supply JavaScript input that triggers an exception and reaches …","severity":"none","published":"2026-09-24","updated":"2026-09-24","sourceUpdated":"2026-09-24T21:25:27.050","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-88388","references":[{"url":"https://github.com/espruino/Espruino/commit/ecd7d43e084ba9aafa8245609347fe0f4383b38c","label":"cve@mitre.org"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-24T20:51:40.267Z","slug":"CVE-2026-88388","body":"## Overview\n\nEspruino 2v29 (commit bffc6d0) contains a stack-based buffer overflow vulnerability in the JavaScript error stack-trace handling path on 64-bit builds. A remote attacker can supply JavaScript input that triggers an exception and reaches jslPrintTokenLineMarker(), which passes the address of a 4-byte int column variable to jsvGetLineAndCol() as a size_t pointer. jsvGetLineAndCol() performs an 8-byte write through the mismatched pointer, overwriting adjacent stack memory.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}