Jsish is a scripting engine and interpreter that, despite a narrow product scope, has achieved prominence in the vulnerability landscape through a concentrated disclosure history. Vulnerabilities affecting the product skew strongly toward critical-severity outcomes and center on memory-safety issues including use-after-free conditions, out-of-bounds writes, NULL-pointer dereferences, and reachable assertions—flaws characteristic of an interpreter implemented in native code where parsing and evaluation state management are complex. The recurring nature of these weakness classes suggests systematic exposure in the engine's core memory-handling paths rather than isolated issues, making each disclosure relevant to any deployment relying on the interpreter. Defenders should treat updates to this product as security-critical and evaluate whether the interpreter is embedded in wider systems where memory-safety vulnerabilities carry outsized risk; live exploitation activity, KEV status, and current exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jsish over time
Signals from CVEs in this vendor scope (53 CVEs).
53 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-65570CRITICAL A type confusion in jsish 2.0 allows incorrect control flow during execution of the OP_NEXT opcode. When an “instanceof” expression uses an array element access as the left-hand op | Dec 29, 2025 | 9.8 | 30 | NO | NO |
CVE-2020-22874CRITICAL Integer overflow vulnerability in function Jsi_ObjArraySizer in jsish before 3.0.8, allows remote attackers to execute arbitrary code. | Jul 13, 2021 | 9.8 | 30 | NO | NO |
CVE-2020-22873CRITICAL Buffer overflow vulnerability in function NumberToPrecisionCmd in jsish before 3.0.7, allows remote attackers to execute arbitrary code. | Jul 13, 2021 | 9.8 | 30 | NO | NO |
CVE-2020-22875CRITICAL Integer overflow vulnerability in function Jsi_ObjSetLength in jsish before 3.0.6, allows remote attackers to execute arbitrary code. | Jul 13, 2021 | 9.8 | 29 | NO | NO |
CVE-2019-1010177CRITICAL Jsish 2.4.70 2.047 is affected by: Use After Free. The impact is: denial of service and possibly arbitrary code execution. The component is: function Jsi_RegExpNew (jsi/jsiRegexp.c | Jul 24, 2019 | 9.8 | 28 | NO | NO |
CVE-2021-46482HIGH Jsish v3.5.0 was discovered to contain a heap buffer overflow via NumberConstructor at src/jsiNumber.c. | Jan 25, 2022 | 7.8 | 26 | NO | NO |
CVE-2024-24189CRITICAL Jsish v3.5.0 (commit 42c694c) was discovered to contain a use-after-free via the SplitChar at ./src/jsiUtils.c. | Feb 7, 2024 | 9.8 | 25 | NO | NO |
CVE-2024-24188CRITICAL Jsish v3.5.0 was discovered to contain a heap-buffer-overflow in ./src/jsiUtils.c. | Feb 7, 2024 | 9.8 | 25 | NO | NO |
CVE-2024-24186CRITICAL Jsish v3.5.0 (commit 42c694c) was discovered to contain a stack-overflow via the component IterGetKeysCallback at /jsish/src/jsiValue.c. | Feb 7, 2024 | 9.8 | 25 | NO | NO |
CVE-2021-46483HIGH Jsish v3.5.0 was discovered to contain a heap buffer overflow via BooleanConstructor at src/jsiBool.c. | Jan 25, 2022 | 7.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (53 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jsish.
Media articles that mention a CVE ID that affects a product developed by Jsish — matched by CVE ID, not by vendor name.