{"id":"CVE-2026-88388","details":"Espruino 2v29 (commit bffc6d0) contains a stack-based buffer overflow vulnerability in the JavaScript error stack-trace handling path on 64-bit builds. A remote attacker can supply JavaScript input that triggers an exception and reaches jslPrintTokenLineMarker(), which passes the address of a 4-byte int column variable to jsvGetLineAndCol() as a size_t pointer. jsvGetLineAndCol() performs an 8-byte write through the mismatched pointer, overwriting adjacent stack memory.","modified":"2026-09-26T08:10:32.448306Z","published":"2026-09-24T00:00:00Z","database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/88xxx/CVE-2026-88388.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/88xxx/CVE-2026-88388.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-88388"},{"type":"FIX","url":"https://github.com/espruino/Espruino/commit/ecd7d43e084ba9aafa8245609347fe0f4383b38c"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/espruino/espruino","events":[{"introduced":"0"},{"fixed":"ecd7d43e084ba9aafa8245609347fe0f4383b38c"}],"database_specific":{"source":"REFERENCES"}}],"versions":["RELEASE_2V29","RELEASE_2V28","RELEASE_2V27","RELEASE_2V26","RELEASE_2V25","RELEASE_2V24","RELEASE_2V23","RELEASE_2V22","RELEASE_2V20","RELEASE_2V18","RELEASE_2V17","RELEASE_2V12","RELEASE_2V11","RELEASE_2V10","RELEASE_2V07","RELEASE_2V06","RELEASE_2V05","RELEASE_2V04","RELEASE_2V03","RELEASE_2V02","RELEASE_1V99","RELEASE_1V98","PIXLJS_REV_1i","RELEASE_1V97","RELEASE_1V96","PIXLJS_REV_1","RELEASE_1V95","HEXBADGE","RELEASE_1V94","RELEASE_1V93","RELEASE_1V92","RELEASE_1V91","RELEASE_1V89","RELEASE_1V90","RELEASE_1V88","RELEASE_1V87","RELEASE_1V86","RELEASE_1V85","esp-2015-10-04","esp8266-2015-10-03","esp8266-2015-10-01","RELEASE_1V79","RELEASE_1V78","RELEASE_1V77","RELEASE_1V76","RELEASE_1V75","RELEASE_1V74","RELEASE_1V73","RELEASE_1V72","RELEASE_1V44","ESPRUINOBOARD_1v3_SEEED"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-88388.json","vanir_signatures_modified":"2026-09-26T08:10:32Z","vanir_signatures":[{"target":{"file":"src/jsvar.c"},"deprecated":false,"digest":{"line_hashes":["111857390762109569997491314424147310013","115624223891494030043665222596295414754","334746935930424047071060083780902345066","79457825122200364883351550636637985388"],"threshold":0.9},"id":"CVE-2026-88388-3cd9690e","signature_type":"Line","signature_version":"v1","source":"https://github.com/espruino/espruino/commit/ecd7d43e084ba9aafa8245609347fe0f4383b38c"},{"digest":{"function_hash":"220271362237484075562535684665826006739","length":1222},"id":"CVE-2026-88388-69ae39a9","signature_type":"Function","signature_version":"v1","source":"https://github.com/espruino/espruino/commit/ecd7d43e084ba9aafa8245609347fe0f4383b38c","target":{"file":"src/jsvar.c","function":"jsvGetString"},"deprecated":false},{"target":{"file":"src/jslex.c","function":"jslGetTokenValueAsString"},"deprecated":false,"digest":{"function_hash":"159025039449948428410325919797687887097","length":530},"id":"CVE-2026-88388-dc10c21a","signature_type":"Function","signature_version":"v1","source":"https://github.com/espruino/espruino/commit/ecd7d43e084ba9aafa8245609347fe0f4383b38c"},{"source":"https://github.com/espruino/espruino/commit/ecd7d43e084ba9aafa8245609347fe0f4383b38c","target":{"file":"src/jslex.c"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["233807574518382640991335543716897052246","237247965892879672983049126434216070296","190473163135012366854073282779379415852","109902505819041516378238503186412347278"]},"id":"CVE-2026-88388-e0501d9d","signature_type":"Line","signature_version":"v1"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}