CVE-2020-25464: Moddable

High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.

Heap buffer overflow at moddable/xs/sources/xsDebug.c in Moddable SDK before before 20200903. The top stack frame is only partially initialized because the stack overflowed while creating the frame. This leads to a crash in the code sending the stack frame to the debugger.

Affected products

  • Moddable Moddable: before os200903 (fixed in os200903)

Published 2020-12-04. Last modified 2026-06-17.