Impact
The uri-js library up to version 4.4.1 contains an improper UTF‑8 decoding issue in the pctDecChars() function. An attacker can provide percent‑encoded input that the routine decodes as overlong or invalid UTF‑8 sequences into ASCII control characters. This flaw is classified as CWE‑176 (Improper Encoding or Decoding) and CWE‑22 (Path Traversal). Because the decoded data is passed to downstream components without further validation, an attacker can inject path‑traversal sequences or CRLF characters that may lead to directory traversal or response‑splitting attacks, potentially enabling remote code execution or other malicious behavior on the target system.
Affected Systems
Affected products are the uri-js library maintained by garycourt. All publicly available releases through version 4.4.1 are vulnerable; the patch is expected in a later release. The library is used in numerous JavaScript projects that parse URLs or file paths, so many systems incorporating these versions are at risk.
Risk and Exploitability
The CVSS score of 6.9 indicates a high impact potential, while the EPSS score of less than 1 % suggests that exploitation likelihood is currently low. The vulnerability is not listed in CISA’s KEV catalog, but because it is input‑validation related, any application that relies on uri‑js for decoding user‑supplied URLs should be considered exposed. The flaw also represents a path traversal weakness (CWE‑22), which may allow traversal of files outside expected directories. Attackers could target exposed web services or API endpoints that accept URLs, constructing payloads that exploit the decoding fault to bypass security controls and cause injection attacks.
OpenCVE Enrichment