Vulnerability GHSA-hp3w-g68c-fv3c

Medium Risk
MEDIUM RISK
CVSS Score: 5.3
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
11 days ago
September 24, 2026 at 03:31 PM UTC
sprintf-js vulnerable to denial of service through unbounded precision specifiers
0.0.7 - 1.1.3
0.0.7 - 1.1.3

Summary

sprintf-js vulnerable to denial of service through unbounded precision specifiers

Details

sprintf-js through 1.1.3 passes unbounded precision specifiers to toFixed, toExponential, and toPrecision methods without validation, causing uncaught RangeError exceptions. Attackers who control format strings can inject precision values exceeding ECMAScript limits to abort calling operations with minimal payload.

Impacted packages

Timeline

Published
11 days ago
September 24, 2026 at 03:31 PM UTC
Last Modified
7 hours ago
October 06, 2026 at 12:00 AM UTC