PT-2026-3428 · Quickjs+1 · Quickjs+1
Mcsky23
·
Published
2026-01-19
·
Updated
2026-01-19
·
CVE-2026-1145
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
quickjs-ng versions up to 0.11.0
Description
A flaw exists in quickjs-ng quickjs due to a heap-based buffer overflow in the
js typed array constructor ta function within the quickjs.c file. This manipulation allows for remote exploitation. An exploit for this issue has been published.Recommendations
Install patch 53aebe66170d545bb6265906fe4324e4477de8b4 to address this issue.
Exploit
Fix
Buffer Overflow
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Quickjs
Quickjs-Ng