Impact
The vulnerability resides in the Lasso Language Tokenizer of BareBones BBEdit and causes an infinite loop when the tokenizer processes a crafted input. This results in resource exhaustion, preventing normal operation and leading to a denial of service. The weakness aligns with CWE-404 (Improper Resource Handling) and CWE-835 (Infinite Loop).
Affected Systems
Affected systems include any installation of BareBones BBEdit through version 15.5.5. The product is listed as BareBones:BBEdit with a CPE indicating use of the Lasso tokenizer component. Upgrading to version 16.0 removes the bug, as noted by the vendor.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. EPSS is not available, and the vulnerability is not present in CISA's KEV catalog. According to the description, an attacker can exploit the flaw remotely, likely by sending a specially crafted input to the tokenizer. While the impact is limited to a DoS, the lack of an exploit‑prevention mechanism means an adversary could repeatedly trigger the infinite loop on any exposed BBEdit instance, potentially disrupting services.
OpenCVE Enrichment