Description
A vulnerability was determined in Cesanta mJS up to 1.26. Affected is the function skip_spaces_and_comments of the file src/mjs_tok.c. Executing a manipulation can lead to heap-based buffer overflow. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-08
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch ASAP
AI Analysis

Impact

The vulnerability is a heap‑based buffer overflow in the function skip_spaces_and_comments within Cesanta mJS up to version 1.26. Executing specific input can corrupt heap memory, causing arbitrary code execution. The issue is disclosed as publicly exploitable and does not currently have a vendor response or patch.

Affected Systems

Cesanta mJS, versions up to and including 1.26. No further version breakdown is available in the current data.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate severity. The EPSS score is unavailable, so current likelihood assessments are uncertain, and the vulnerability is not flagged in the CISA KEV catalog. The attack can be launched remotely, suggesting that exposed network interfaces or untrusted input could be abused. In absence of a patch, the risk remains moderate but with potential for critical impact if exploitation succeeds.

Generated by OpenCVE AI on September 9, 2026 at 13:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Cesanta mJS patch or newer release when it becomes available
  • Restrict or temporarily disable exposure of the mJS component, limiting remote input to trusted sources
  • If possible, filter or validate input to skip_spaces_and_comments, mitigating the overflow risk

Generated by OpenCVE AI on September 9, 2026 at 13:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in Cesanta mJS up to 1.26. Affected is the function skip_spaces_and_comments of the file src/mjs_tok.c. Executing a manipulation can lead to heap-based buffer overflow. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
Title Cesanta mJS mjs_tok.c skip_spaces_and_comments heap-based overflow
First Time appeared Cesanta
Cesanta mjs
Weaknesses CWE-119
CWE-122
CPEs cpe:2.3:a:cesanta:mjs:*:*:*:*:*:*:*:*
Vendors & Products Cesanta
Cesanta mjs
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-08T19:08:36.351Z

Reserved: 2026-09-08T11:09:32.652Z

Link: CVE-2026-86716

cve-icon Vulnrichment

Updated: 2026-09-08T19:08:07.219Z

cve-icon NVD

Status : Deferred

Published: 2026-09-08T19:20:17.357

Modified: 2026-09-08T20:18:53.110

Link: CVE-2026-86716

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-12T06:15:03Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-122

    Heap-based Buffer Overflow