Impact
The vulnerability is a heap‑based buffer overflow in the function skip_spaces_and_comments within Cesanta mJS up to version 1.26. Executing specific input can corrupt heap memory, causing arbitrary code execution. The issue is disclosed as publicly exploitable and does not currently have a vendor response or patch.
Affected Systems
Cesanta mJS, versions up to and including 1.26. No further version breakdown is available in the current data.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity. The EPSS score is unavailable, so current likelihood assessments are uncertain, and the vulnerability is not flagged in the CISA KEV catalog. The attack can be launched remotely, suggesting that exposed network interfaces or untrusted input could be abused. In absence of a patch, the risk remains moderate but with potential for critical impact if exploitation succeeds.
OpenCVE Enrichment