CVE-2026-93751 - Medium Severity Vulnerability
Vulnerable Library - uri-js-4.4.1.tgz
An RFC 3986/3987 compliant, scheme extendable URI/IRI parsing/validating/resolving library for JavaScript.
Library home page: https://registry.npmjs.org/uri-js/-/uri-js-4.4.1.tgz
Sample Path to Dependency File: /package.json
Path to vulnerable library: /node_modules/uri-js/package.json
Dependency Hierarchy:
- eslint-8.3.0.tgz (Root Library)
- ajv-6.12.6.tgz
- ❌ uri-js-4.4.1.tgz (Vulnerable Library)
Found in HEAD commit: 977ea6ccaaf2045985ee40cacd5f6d676fa1a047
Found in base branch: master
Vulnerability Details
uri-js through 4.4.1 contains an improper UTF-8 decoding vulnerability in pctDecChars() that decodes invalid and overlong percent-encoded sequences into ASCII metacharacters. Attackers can craft percent-encoded payloads to bypass platform decoder validation and inject path traversal or CRLF sequences that downstream consumers process without filtering.
Publish Date: 2026-09-18
URL: CVE-2026-93751
CVSS 3 Score Details (6.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: Low
- Integrity Impact: Low
- Availability Impact: None
For more information on CVSS3 Scores, click here.
Step up your Open Source Security Game with Mend here
CVE-2026-93751 - Medium Severity Vulnerability
An RFC 3986/3987 compliant, scheme extendable URI/IRI parsing/validating/resolving library for JavaScript.
Library home page: https://registry.npmjs.org/uri-js/-/uri-js-4.4.1.tgz
Sample Path to Dependency File: /package.json
Path to vulnerable library: /node_modules/uri-js/package.json
Dependency Hierarchy:
Found in HEAD commit: 977ea6ccaaf2045985ee40cacd5f6d676fa1a047
Found in base branch: master
uri-js through 4.4.1 contains an improper UTF-8 decoding vulnerability in pctDecChars() that decodes invalid and overlong percent-encoded sequences into ASCII metacharacters. Attackers can craft percent-encoded payloads to bypass platform decoder validation and inject path traversal or CRLF sequences that downstream consumers process without filtering.
Publish Date: 2026-09-18
URL: CVE-2026-93751
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: Low
- Integrity Impact: Low
- Availability Impact: None
For more information on CVSS3 Scores, click here.Step up your Open Source Security Game with Mend here