Espruino is a JavaScript runtime and firmware platform for resource-constrained microcontrollers and embedded systems, positioning itself as an accessible entry point for embedded development. Vulnerabilities affecting the platform skew toward serious outcomes, with an elevated share reaching critical severity, and recur through memory-safety weakness classes including out-of-bounds writes and reads, buffer overflows, and improper bounds checking—endemic to interpreter codebases operating in memory-limited environments. Defenders deploying Espruino-based devices should monitor vendor advisories and consider memory-safety implications when integrating user-supplied code; current severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Espruino over time
Signals from CVEs in this vendor scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-19693CRITICAL An issue found in Espruino Espruino 6ea4c0a allows an attacker to execute arbitrrary code via oldFunc parameter of the jswrap_object.c:jswrap_function_replacewith endpoint. | Apr 4, 2023 | 9.8 | 31 | NO | NO |
CVE-2020-22884CRITICAL Buffer overflow vulnerability in function jsvGetStringChars in Espruino before RELEASE_2V09, allows remote attackers to execute arbitrary code. | Jul 13, 2021 | 9.8 | 29 | NO | NO |
CVE-2022-25465HIGH Espruino 2v11 release was discovered to contain a stack buffer overflow via src/jsvar.c in jsvGetNextSibling. | Mar 5, 2022 | 7.8 | 26 | NO | NO |
CVE-2022-25044HIGH Espruino 2v11.251 was discovered to contain a stack buffer overflow via src/jsvar.c in jsvNewFromString. | Mar 5, 2022 | 7.8 | 26 | NO | NO |
CVE-2021-46325HIGH Espruino 2v10.246 was discovered to contain a stack buffer overflow via src/jsutils.c in vcbprintf. | Jan 20, 2022 | 7.8 | 25 | NO | NO |
CVE-2021-46324HIGH Espruino 2v11.251 was discovered to contain a stack buffer overflow via src/jsvar.c in jsvNewFromString. | Jan 20, 2022 | 7.8 | 25 | NO | NO |
CVE-2020-23257HIGH Buffer Overflow vulnerability found in Espruino 2v05.41 allows an attacker to cause a denial of service via the function jsvGarbageCollectMarkUsed in file src/jsvar.c. | Apr 4, 2023 | 7.5 | 23 | NO | NO |
CVE-2018-11595HIGH Espruino before 1.99 allows attackers to cause a denial of service (application crash) and a potential Escalation of Privileges with a user crafted input file via a Buffer Overflow | May 31, 2018 | 7.8 | 23 | NO | NO |
CVE-2018-11598HIGH Espruino before 1.99 allows attackers to cause a denial of service (application crash) and a potential Information Disclosure with user crafted input files via a Buffer Overflow or | May 31, 2018 | 7.1 | 22 | NO | NO |
CVE-2018-11593HIGH Espruino before 1.99 allows attackers to cause a denial of service (application crash) and potential Information Disclosure with a user crafted input file via a Buffer Overflow dur | May 31, 2018 | 7.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (19 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Espruino.
Media articles that mention a CVE ID that affects a product developed by Espruino — matched by CVE ID, not by vendor name.