Samsung.escargot is vulnerable to Out-of-bounds Write
62
Medium Risk
Samsung.escargot truncates a class instance field initialization count to uint16_t in parseClassBody (CVE-2026-86315), so a class whose entry count exceeds UINT16_MAX causes an out-of-bounds write. The same release also has a heap buffer overflow in Interpreter::interpret (CVE-2026-58306), a stack buffer overflow (CVE-2026-58303), and an out-of-bounds read and write in ArrayBuffer.prototype.transfer (CVE-2026-58304). CVE-2026-58305 is type confusion in arrayDefineOwnPropertyBySpreadElementOperation that allows pointer manipulation, and CVE-2026-58307 is an out-of-bounds read plus a reachable assertion on paths such as String::charAt and asDisposableResourceRecord that can leak memory. The fix adds bounds and type checks on these paths.
You are affected if you are using a version that falls within the vulnerable range and you execute untrusted or externally supplied JavaScript with the engine.
Samsung.escargot is vulnerable to Out-of-bounds Write in versions 1.0.0 - 4.3.0.
Upgrade the Samsung.escargot library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.