Impact
A flaw exists in the Java Language Module of BareBones BBEdit that can be manipulated to trigger uncontrolled recursion. When triggered, the recursion exhausts the stack and can cause the application to enter an infinite loop, potentially rendering the program unresponsive. The effect is a denial‑of‑service condition that can be triggered remotely by an attacker who can supply crafted input to the vulnerable component.
Affected Systems
BareBones BBEdit versions up to and including 15.5.5 are affected. The vulnerability is fixed in version 16.0 and later.
Risk and Exploitability
The CVSS base score of 5.3 indicates a moderate severity, and the vulnerability is not listed in CISA’s KEV catalog. EPSS information is not available, so the likelihood of exploitation in the wild is unclear. Based on the description, it is inferred that the attack vector is remote exploitation via the Java Language Module, requiring an attacker to send specially crafted input to the application. If exploited, the attacker can cause the program to consume all stack space and to become unresponsive, potentially allowing denial of service to legitimate users.
OpenCVE Enrichment