CVE-2020-25465: Moddable

High severity, CVSS 7.5. EPSS: 1.6% chance of exploitation in the next 30 days.

Null Pointer Dereference. in xObjectBindingFromExpression at moddable/xs/sources/xsSyntaxical.c:3419 in Moddable SDK before OS200908 causes a denial of service (SEGV).

Affected products

  • Moddable Moddable: before os200908 (fixed in os200908)

Published 2020-12-04. Last modified 2026-06-17.