CVE-2018-11591: Espruino

Medium severity, CVSS 5.5. EPSS: 1% chance of exploitation in the next 30 days.

Espruino before 1.98 allows attackers to cause a denial of service (application crash) with a user crafted input file via a NULL pointer dereference during syntax parsing. This was addressed by adding validation for a debug trace print statement in jsvar.c.

Affected products

  • Espruino Espruino: before 1.98 (fixed in 1.98)

Published 2018-05-31. Last modified 2026-06-17.