{"id":"CVE-2026-88390","details":"An out-of-bounds write vulnerability in jslGetTokenValueAsString() in Espruino 2v29 (commit bffc6d0) allows crafted JavaScript input containing an overlong token to trigger a one-byte write beyond the JsLex.token buffer in RELEASE/NO_ASSERT builds. The out-of-bounds write corrupts the adjacent tokenValue pointer, resulting in memory corruption and potentially causing application crashes or denial of service.","modified":"2026-09-26T08:10:32.144410Z","published":"2026-09-24T00:00:00Z","database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/88xxx/CVE-2026-88390.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/88xxx/CVE-2026-88390.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-88390"},{"type":"REPORT","url":"https://github.com/espruino/Espruino/issues/2744"},{"type":"FIX","url":"https://github.com/espruino/Espruino/commit/ecd7d43e084ba9aafa8245609347fe0f4383b38c"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/espruino/espruino","events":[{"introduced":"0"},{"fixed":"ecd7d43e084ba9aafa8245609347fe0f4383b38c"}],"database_specific":{"source":"REFERENCES"}}],"versions":["RELEASE_2V29","RELEASE_2V28","RELEASE_2V27","RELEASE_2V26","RELEASE_2V25","RELEASE_2V24","RELEASE_2V23","RELEASE_2V22","RELEASE_2V20","RELEASE_2V18","RELEASE_2V17","RELEASE_2V12","RELEASE_2V11","RELEASE_2V10","RELEASE_2V07","RELEASE_2V06","RELEASE_2V05","RELEASE_2V04","RELEASE_2V03","RELEASE_2V02","RELEASE_1V99","RELEASE_1V98","PIXLJS_REV_1i","RELEASE_1V97","RELEASE_1V96","PIXLJS_REV_1","RELEASE_1V95","HEXBADGE","RELEASE_1V94","RELEASE_1V93","RELEASE_1V92","RELEASE_1V91","RELEASE_1V89","RELEASE_1V90","RELEASE_1V88","RELEASE_1V87","RELEASE_1V86","RELEASE_1V85","esp-2015-10-04","esp8266-2015-10-03","esp8266-2015-10-01","RELEASE_1V79","RELEASE_1V78","RELEASE_1V77","RELEASE_1V76","RELEASE_1V75","RELEASE_1V74","RELEASE_1V73","RELEASE_1V72","RELEASE_1V44","ESPRUINOBOARD_1v3_SEEED"],"database_specific":{"vanir_signatures_modified":"2026-09-26T08:10:32Z","vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["111857390762109569997491314424147310013","115624223891494030043665222596295414754","334746935930424047071060083780902345066","79457825122200364883351550636637985388"],"threshold":0.9},"id":"CVE-2026-88390-3cd9690e","signature_type":"Line","signature_version":"v1","source":"https://github.com/espruino/espruino/commit/ecd7d43e084ba9aafa8245609347fe0f4383b38c","target":{"file":"src/jsvar.c"}},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/espruino/espruino/commit/ecd7d43e084ba9aafa8245609347fe0f4383b38c","target":{"file":"src/jsvar.c","function":"jsvGetString"},"deprecated":false,"digest":{"function_hash":"220271362237484075562535684665826006739","length":1222},"id":"CVE-2026-88390-69ae39a9"},{"digest":{"function_hash":"159025039449948428410325919797687887097","length":530},"id":"CVE-2026-88390-dc10c21a","signature_type":"Function","signature_version":"v1","source":"https://github.com/espruino/espruino/commit/ecd7d43e084ba9aafa8245609347fe0f4383b38c","target":{"file":"src/jslex.c","function":"jslGetTokenValueAsString"},"deprecated":false},{"signature_version":"v1","source":"https://github.com/espruino/espruino/commit/ecd7d43e084ba9aafa8245609347fe0f4383b38c","target":{"file":"src/jslex.c"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["233807574518382640991335543716897052246","237247965892879672983049126434216070296","190473163135012366854073282779379415852","109902505819041516378238503186412347278"]},"id":"CVE-2026-88390-e0501d9d","signature_type":"Line"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-88390.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"}]}