CVE-2020-25461: Moddable

High severity, CVSS 7.5. EPSS: 1.3% chance of exploitation in the next 30 days.

Invalid Memory Access in the fxProxyGetter function in moddable/xs/sources/xsProxy.c in Moddable SDK before OS200908 causes a denial of service (SEGV).

Affected products

  • Moddable Moddable: before os200908 (fixed in os200908)

Published 2020-12-04. Last modified 2026-06-17.