CVE-2018-11593: Espruino

High severity, CVSS 7.1. EPSS: 1.2% chance of exploitation in the next 30 days.

Espruino before 1.99 allows attackers to cause a denial of service (application crash) and potential Information Disclosure with a user crafted input file via a Buffer Overflow during syntax parsing because strncpy is misused in jslex.c.

Affected products

  • Espruino Espruino: before 1.99 (fixed in 1.99)

Published 2018-05-31. Last modified 2026-06-17.