High severity7.8NVD Advisory· Published Aug 13, 2020· Updated Jun 17, 2026
CVE-2020-24345
CVE-2020-24345
Description
JerryScript through 2.3.0 allows stack consumption via function a(){new new Proxy(a,{})}JSON.parse("[]",a). NOTE: the vendor states that the problem is the lack of the --stack-limit option
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:jerryscript:jerryscript:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:jerryscript:jerryscript:*:*:*:*:*:*:*:*range: <=2.3.0
- (no CPE)range: <=2.3.0
- JerryScript/JerryScriptdescription
Patches
Vulnerability mechanics
References
1- github.com/jerryscript-project/jerryscript/issues/3977nvdExploitIssue TrackingPatchThird Party Advisory
News mentions
0No linked articles in our index yet.