Description
Stack-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers.

This issue affects Escargot: before b30b63fc63b403907d8137da1c65aaa4521fe74e.
Published: 2026-07-09
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a stack‑based buffer overflow in the Samsung Open Source Escargot JavaScript engine. The overflow allows malicious or malformed script input to overwrite local variables on the stack, potentially corrupting memory, leading to unauthorized code execution or causing a crash. This flaw is classified as CWE‑121 and carries a CVSS score of 6.1, indicating moderate impact on confidentiality, integrity, and availability of applications that embed the engine.

Affected Systems

The affected product is the Samsung Open Source Escargot JavaScript engine. Builds and releases prior to the commit identified by b30b63fc63b403907d8137da1c65aaa4521fe74e contain the flaw. Any deployment that incorporates this version of Escargot is vulnerable until the patch from pull request 1585 is applied or the engine is upgraded to a later commit.

Risk and Exploitability

The CVSS score of 6.1 reflects moderate severity, while the EPSS score is reported as less than 1%, suggesting a low likelihood of active exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the likely attack vector would involve delivering a crafted JavaScript payload to an application that uses Escargot, but the CVE entry does not explicitly state the vector. Systems that expose the engine to untrusted input constitute the principal risk surface.

Generated by OpenCVE AI on July 26, 2026 at 15:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Escargot to a commit after b30b63fc63b403907d8137da1c65aaa4521fe74e or apply the patch included in pull request 1585.
  • If immediate upgrade is not possible, restrict the engine’s execution of untrusted or externally supplied scripts until the fix is deployed.
  • Monitor application and system logs for signs of abnormal behavior that might indicate exploitation attempts, and investigate any anomalies promptly.

Generated by OpenCVE AI on July 26, 2026 at 15:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 26 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title Stack-Based Buffer Overflow in Samsung Escargot JavaScript Engine

Tue, 21 Jul 2026 01:15:00 +0000

Type Values Removed Values Added
Title Stack-based buffer overflow in Escargot JavaScript engine

Thu, 16 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Stack-based buffer overflow in Escargot JavaScript engine

Mon, 13 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Stack-based Buffer Overflow in Samsung Escargot JavaScript Engine

Sun, 12 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Title Stack-based Buffer Overflow in Samsung Escargot JavaScript Engine

Sat, 11 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Stack-based Buffer Overflow in Samsung Open Source Escargot

Fri, 10 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Title Stack-based Buffer Overflow in Samsung Open Source Escargot

Thu, 09 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Samsung Open Source
Samsung Open Source escargot
Vendors & Products Samsung Open Source
Samsung Open Source escargot

Thu, 09 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Description Stack-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot: before b30b63fc63b403907d8137da1c65aaa4521fe74e.
Weaknesses CWE-121
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H'}


Subscriptions

Samsung Open Source Escargot
cve-icon MITRE

Status: PUBLISHED

Assigner: samsung.tv_appliance

Published:

Updated: 2026-07-09T12:17:48.514Z

Reserved: 2026-06-30T01:49:44.822Z

Link: CVE-2026-58303

cve-icon Vulnrichment

Updated: 2026-07-09T12:17:30.461Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T15:45:08Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow