Loading HuntDB...

GHSA-g533-xq5w-jmf3

GitHub Security Advisory

node-stringbuilder vulnerable to Out-of-bounds Read

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

All versions of the package node-stringbuilder are vulnerable to Out-of-bounds Read due to incorrect memory length calculation, by calling ToBuffer, ToString, or CharAt on a StringBuilder object with a non-empty string value input. It's possible to return previously allocated memory, for example, by providing negative indexes, leading to an Information Disclosure.

Affected Packages

npm node-stringbuilder
Affected versions: 0 (last affected: 2.2.7)

Related CVEs

Key Information

GHSA ID
GHSA-g533-xq5w-jmf3
Published
July 10, 2024 6:33 AM
Last Modified
July 10, 2024 8:43 PM
CVSS Score
7.5 /10
Primary Ecosystem
npm
Primary Package
node-stringbuilder
GitHub Reviewed
✓ Yes

Dataset

Last updated: June 15, 2025 6:24 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.