CVE-2024-27088: Medikoo ES5-Ext

Medium severity, CVSS 5.5. EPSS: 0.5% chance of exploitation in the next 30 days.

es5-ext contains ECMAScript 5 extensions. Passing functions with very long names or complex default argument names into `function#copy` or `function#toStringTokens` may cause the script to stall. The vulnerability is patched in v0.10.63.

Affected products

  • Medikoo ES5-Ext: from 0.10.0, before 0.10.63 (fixed in 0.10.63)

Published 2024-02-26. Last modified 2026-06-17.