Espruino 2v29 (commit bffc6d0) contains a NULL pointer dereference vulnerability in jslGetRawString() in src/jslex.c. Crafted raw/binary string input can cause the lexer to pass a NULL iterator target to jsvLockAgain(). In RELEASE/NO_ASSERT builds, the missing assertion guard allows a write through the NULL pointer, resulting in memory corruption and application termination or denial of service.
{
"cna_assigner": "mitre",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/88xxx/CVE-2026-88389.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-88389.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"295177405760716288977799640039725511026",
"152972243292387839861914974551506068910",
"334234037081048451400513214422052448601",
"145682203710813656440825243329983209379",
"308342574319288859276529582266438180428",
"146411559443613239898560195903938587414"
],
"threshold": 0.9
},
"id": "CVE-2026-88389-0d956529",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/espruino/espruino/commit/0db0663ac5201a6fea68094b45da673edec45187",
"target": {
"file": "src/jslex.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "260114895519927947046375373513885386024",
"length": 857
},
"id": "CVE-2026-88389-294dad8e",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/espruino/espruino/commit/0db0663ac5201a6fea68094b45da673edec45187",
"target": {
"file": "src/jslex.c",
"function": "jslGetRawString"
}
}
]
"2026-10-02T08:13:40Z"