Moddable develops a compact embedded systems and IoT runtime platform, including its SDK and XS interpreter, that targets resource-constrained devices and microcontrollers. The vendor's vulnerability footprint, while narrow in product scope, recurs through weakness classes including out-of-bounds writes, NULL-pointer dereferences, and resource-exhaustion conditions that are characteristic of low-level runtime and memory-management code. A meaningful share of the vendor's disclosures reach serious severity, reflecting the critical nature of memory safety in embedded interpreters and the difficulty of recovery in deployment environments with limited redundancy. Defenders deploying Moddable-based IoT and embedded applications should monitor the vendor's advisories and maintain awareness of the underlying runtime's security posture, since patches often require firmware updates across distributed device populations. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Moddable over time
Signals from CVEs in this vendor scope (25 CVEs).
25 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-16366CRITICAL In XS 9.0.0 in Moddable SDK OS180329, there is a heap-based buffer overflow in fxBeginHost in xsAPI.c when called from fxRunDefine in xsRun.c, as demonstrated by crafted JavaScript | Sep 16, 2019 | 9.8 | 29 | NO | NO |
CVE-2021-46326HIGH Moddable SDK v11.5.0 was discovered to contain a heap-buffer-overflow via the component __asan_memcpy. | Jan 20, 2022 | 7.8 | 25 | NO | NO |
CVE-2021-29326HIGH OpenSource Moddable v10.5.0 was discovered to contain a heap buffer overflow in the fxIDToString function at /moddable/xs/sources/xsSymbol.c. | Nov 19, 2021 | 7.8 | 25 | NO | NO |
CVE-2021-29325HIGH OpenSource Moddable v10.5.0 was discovered to contain a heap buffer overflow in the fx_String_prototype_repeat function at /moddable/xs/sources/xsString.c. | Nov 19, 2021 | 7.8 | 25 | NO | NO |
CVE-2021-29324HIGH OpenSource Moddable v10.5.0 was discovered to contain a stack overflow via the component /moddable/xs/sources/xsScript.c. | Nov 19, 2021 | 7.8 | 25 | NO | NO |
CVE-2022-29368HIGH Moddable commit before 135aa9a4a6a9b49b60aa730ebc3bcc6247d75c45 was discovered to contain an out-of-bounds read via the function fxUint8Getter at /moddable/xs/sources/xsDataView.c. | May 12, 2022 | 7.1 | 24 | NO | NO |
CVE-2021-29329HIGH OpenSource Moddable v10.5.0 was discovered to contain a stack overflow in the fxBinaryExpressionNodeDistribute function at /moddable/xs/sources/xsTree.c. | Nov 19, 2021 | 7.8 | 24 | NO | NO |
CVE-2021-29327HIGH OpenSource Moddable v10.5.0 was discovered to contain a heap buffer overflow in the fx_ArrayBuffer function at /moddable/xs/sources/xsDataView.c. | Nov 19, 2021 | 7.8 | 24 | NO | NO |
CVE-2020-25464HIGH Heap buffer overflow at moddable/xs/sources/xsDebug.c in Moddable SDK before before 20200903. The top stack frame is only partially initialized because the stack overflowed while c | Dec 4, 2020 | 7.5 | 24 | NO | NO |
CVE-2020-25462CRITICAL Heap buffer overflow in the fxCheckArrowFunction function at moddable/xs/sources/xsSyntaxical.c:3562 in Moddable SDK before OS200903. | Dec 4, 2020 | 9.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (25 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Moddable.
Media articles that mention a CVE ID that affects a product developed by Moddable — matched by CVE ID, not by vendor name.