Description
uri-js through 4.4.1 contains an improper UTF-8 decoding vulnerability in pctDecChars() that decodes invalid and overlong percent-encoded sequences into ASCII metacharacters. Attackers can craft percent-encoded payloads to bypass platform decoder validation and inject path traversal or CRLF sequences that downstream consumers process without filtering.
Published: 2026-09-18
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The uri-js library up to version 4.4.1 contains an improper UTF‑8 decoding issue in the pctDecChars() function. An attacker can provide percent‑encoded input that the routine decodes as overlong or invalid UTF‑8 sequences into ASCII control characters. This flaw is classified as CWE‑176 (Improper Encoding or Decoding) and CWE‑22 (Path Traversal). Because the decoded data is passed to downstream components without further validation, an attacker can inject path‑traversal sequences or CRLF characters that may lead to directory traversal or response‑splitting attacks, potentially enabling remote code execution or other malicious behavior on the target system.

Affected Systems

Affected products are the uri-js library maintained by garycourt. All publicly available releases through version 4.4.1 are vulnerable; the patch is expected in a later release. The library is used in numerous JavaScript projects that parse URLs or file paths, so many systems incorporating these versions are at risk.

Risk and Exploitability

The CVSS score of 6.9 indicates a high impact potential, while the EPSS score of less than 1 % suggests that exploitation likelihood is currently low. The vulnerability is not listed in CISA’s KEV catalog, but because it is input‑validation related, any application that relies on uri‑js for decoding user‑supplied URLs should be considered exposed. The flaw also represents a path traversal weakness (CWE‑22), which may allow traversal of files outside expected directories. Attackers could target exposed web services or API endpoints that accept URLs, constructing payloads that exploit the decoding fault to bypass security controls and cause injection attacks.

Generated by OpenCVE AI on September 23, 2026 at 01:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the uri-js library to a version that contains the decoding fix; verify that overlong and invalid percent‑encoded sequences are correctly rejected.
  • Add a defensive check before passing user‑supplied URLs to uri‑js: validate that all percent‑encoded sequences conform to UTF‑8 encoding rules and reject inputs with overlong or malformed encodings.
  • Audit all downstream code that receives decoded URL components for path‑traversal or header injection vulnerabilities, and apply appropriate sanitization or access‑control checks.

Generated by OpenCVE AI on September 23, 2026 at 01:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-22
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 21 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description uri-js through 4.4.1 contains an improper UTF-8 decoding vulnerability in pctDecChars() that decodes invalid and overlong percent-encoded sequences into ASCII metacharacters. Attackers can craft percent-encoded payloads to bypass platform decoder validation and inject path traversal or CRLF sequences that downstream consumers process without filtering.
Title uri-js through 4.4.1 Improper UTF-8 Decoding via pctDecChars
First Time appeared Garycourt
Garycourt uri-js
Weaknesses CWE-176
CPEs cpe:2.3:a:garycourt:uri-js:*:*:*:*:*:*:*:*
Vendors & Products Garycourt
Garycourt uri-js
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Garycourt Uri-js
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:23:10.183Z

Reserved: 2026-09-18T16:30:18.137Z

Link: CVE-2026-93751

cve-icon Vulnrichment

Updated: 2026-09-21T16:28:55.723Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T18:18:34.177

Modified: 2026-09-22T20:25:55.870

Link: CVE-2026-93751

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-18T17:51:36Z

Links: CVE-2026-93751 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T01:45:19Z

Weaknesses
  • CWE-176

    Improper Handling of Unicode Encoding

  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')