PatchSiren

Espruino CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Espruino CVE published 2026-09-24

CVE-2026-88388

A stack-based buffer overflow vulnerability exists in Espruino 2v29 (commit bffc6d0) on 64-bit builds, affecting JavaScript error stack-trace handling. A remote attacker can trigger an exception to reach jslPrintTokenLineMarker(), causing an 8-byte write through a mismatched pointer, overwriting adjacent stack memory. This HIGH-severity vulnerability could allow remote attackers to execute arbitrary code [truncated]