CVE-2026-86716

    Dashboard / Vulnerabilities / CVE-2026-86716

    CVE-2026-86716

    Published: 8 Sept 2026Last Modified: 10 Sept 2026

    Summary: Cesanta mJS mjs_tok.c skip_spaces_and_comments heap-based overflow

    Details: A vulnerability was determined in Cesanta mJS up to 1.26. Affected is the function skip_spaces_and_comments of the file src/mjs_tok.c. Executing a manipulation can lead to heap-based buffer overflow. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- 422ca2706b4a334584341c2fc7e4c6f125280f69
    Fixed -None

    Affected versions

    1.10

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2026-86716 | CVE-DB