CVE-2023-50044: Cesanta Mjs

Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.

Cesanta MJS 2.20.0 has a getprop_builtin_foreign out-of-bounds read if a Built-in API name occurs in a substring of an input string.

Affected products

Published 2023-12-20. Last modified 2026-06-17.