{"id":"CVE-2026-88389","details":"Espruino 2v29 (commit bffc6d0) contains a NULL pointer dereference vulnerability in jslGetRawString() in src/jslex.c. Crafted raw/binary string input can cause the lexer to pass a NULL iterator target to jsvLockAgain(). In RELEASE/NO_ASSERT builds, the missing assertion guard allows a write through the NULL pointer, resulting in memory corruption and application termination or denial of service.","modified":"2026-10-02T08:13:40.508624Z","published":"2026-09-25T00:00:00Z","database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/88xxx/CVE-2026-88389.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/88xxx/CVE-2026-88389.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-88389"},{"type":"REPORT","url":"https://github.com/espruino/Espruino/issues/2745"},{"type":"FIX","url":"https://github.com/espruino/Espruino/commit/0db0663ac5201a6fea68094b45da673edec45187"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/espruino/espruino","events":[{"introduced":"0"},{"fixed":"0db0663ac5201a6fea68094b45da673edec45187"}],"database_specific":{"source":"REFERENCES"}}],"versions":["RELEASE_2V29","RELEASE_2V28","RELEASE_2V27","RELEASE_2V26","RELEASE_2V25","RELEASE_2V24","RELEASE_2V23","RELEASE_2V22","RELEASE_2V20","RELEASE_2V18","RELEASE_2V17","RELEASE_2V12","RELEASE_2V11","RELEASE_2V10","RELEASE_2V07","RELEASE_2V06","RELEASE_2V05","RELEASE_2V04","RELEASE_2V03","RELEASE_2V02","RELEASE_1V99","RELEASE_1V98","PIXLJS_REV_1i","RELEASE_1V97","RELEASE_1V96","PIXLJS_REV_1","RELEASE_1V95","HEXBADGE","RELEASE_1V94","RELEASE_1V93","RELEASE_1V92","RELEASE_1V91","RELEASE_1V89","RELEASE_1V90","RELEASE_1V88","RELEASE_1V87","RELEASE_1V86","RELEASE_1V85","esp-2015-10-04","esp8266-2015-10-03","esp8266-2015-10-01","RELEASE_1V79","RELEASE_1V78","RELEASE_1V77","RELEASE_1V76","RELEASE_1V75","RELEASE_1V74","RELEASE_1V73","RELEASE_1V72","RELEASE_1V44","ESPRUINOBOARD_1v3_SEEED"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-88389.json","vanir_signatures_modified":"2026-10-02T08:13:40Z","vanir_signatures":[{"signature_type":"Line","signature_version":"v1","source":"https://github.com/espruino/espruino/commit/0db0663ac5201a6fea68094b45da673edec45187","target":{"file":"src/jslex.c"},"deprecated":false,"digest":{"line_hashes":["295177405760716288977799640039725511026","152972243292387839861914974551506068910","334234037081048451400513214422052448601","145682203710813656440825243329983209379","308342574319288859276529582266438180428","146411559443613239898560195903938587414"],"threshold":0.9},"id":"CVE-2026-88389-0d956529"},{"deprecated":false,"digest":{"function_hash":"260114895519927947046375373513885386024","length":857},"id":"CVE-2026-88389-294dad8e","signature_type":"Function","signature_version":"v1","source":"https://github.com/espruino/espruino/commit/0db0663ac5201a6fea68094b45da673edec45187","target":{"file":"src/jslex.c","function":"jslGetRawString"}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}