An out-of-bounds write vulnerability in jslGetTokenValueAsString() in Espruino 2v29 (commit bffc6d0) allows crafted JavaScript input containing an overlong token to trigger a one-byte write beyond the JsLex.token buffer in RELEASE/NO_ASSERT builds. The out-of-bounds write corrupts the adjacent tokenValue pointer, resulting in memory corruption and potentially causing application crashes or denial of service.
{
"cna_assigner": "mitre",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/88xxx/CVE-2026-88390.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-88390.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"111857390762109569997491314424147310013",
"115624223891494030043665222596295414754",
"334746935930424047071060083780902345066",
"79457825122200364883351550636637985388"
],
"threshold": 0.9
},
"id": "CVE-2026-88390-3cd9690e",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/espruino/espruino/commit/ecd7d43e084ba9aafa8245609347fe0f4383b38c",
"target": {
"file": "src/jsvar.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "220271362237484075562535684665826006739",
"length": 1222
},
"id": "CVE-2026-88390-69ae39a9",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/espruino/espruino/commit/ecd7d43e084ba9aafa8245609347fe0f4383b38c",
"target": {
"file": "src/jsvar.c",
"function": "jsvGetString"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "159025039449948428410325919797687887097",
"length": 530
},
"id": "CVE-2026-88390-dc10c21a",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/espruino/espruino/commit/ecd7d43e084ba9aafa8245609347fe0f4383b38c",
"target": {
"file": "src/jslex.c",
"function": "jslGetTokenValueAsString"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"233807574518382640991335543716897052246",
"237247965892879672983049126434216070296",
"190473163135012366854073282779379415852",
"109902505819041516378238503186412347278"
],
"threshold": 0.9
},
"id": "CVE-2026-88390-e0501d9d",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/espruino/espruino/commit/ecd7d43e084ba9aafa8245609347fe0f4383b38c",
"target": {
"file": "src/jslex.c"
}
}
]
"2026-09-26T08:10:32Z"