Impact
The decoder function readFromDataView in the lib0 library prior to version 0.2.119 can be fed crafted input that causes it to read beyond the intended data view. This out‑of‑bounds read exposes contents of adjacent process memory, potentially leaking sensitive information such as credentials or logs. The weakness is classified as CWE‑125, Out‑of‑Bounds Read.
Affected Systems
The vulnerability affects any deployment that uses the dmonad:lib0 library with a version earlier than 0.2.119. Systems that import the library through npm, yarn or other package managers and integrate it into a browser, Node.js or other runtime environments are therefore impacted.
Risk and Exploitability
The CVSS score of 8.6 indicates a high severity vulnerability. Because the EPSS score is not available, the likelihood of current exploitation is uncertain, but the fact that it is not listed in the CISA KEV catalog suggests it has not yet been actively exploited. The attack likely requires an attacker to supply malicious input to the library, such as a corrupted data stream or a manipulated network packet, and the vulnerability could be exploited in any context where the library generates a decoder for untrusted data, including remote web applications and local applications processing external files.
OpenCVE Enrichment