CVE-2024-21524
JavaScript vulnerability analysis and mitigation

Overview

CVE-2024-21524 affects all versions of the node-stringbuilder package, which was discovered in July 2024. The vulnerability is classified as an Out-of-bounds Read vulnerability due to incorrect memory length calculation when calling specific methods on a StringBuilder object with a non-empty string value input (Snyk Advisory, NVD).

Technical details

The vulnerability occurs when calling ToBuffer, ToString, or CharAt methods on a StringBuilder object with a non-empty string value input. The issue stems from incorrect memory length calculation, which allows access to previously allocated memory through negative indexes. The vulnerability has received a CVSS v3.1 base score of 9.1 (Critical) from NVD and 8.2 (High) from Snyk, indicating its severe nature (NVD, GitHub POC).

Impact

The vulnerability can lead to Information Disclosure by allowing attackers to access previously allocated memory. This could potentially expose sensitive information that was previously stored in memory. The vulnerability requires no authentication and can be exploited remotely (Snyk Advisory).

Exploitability

A proof-of-concept exploit has been published demonstrating the vulnerability. The exploit involves calling the affected methods with negative indexes, which can result in accessing out-of-bounds memory locations. The vulnerability can be triggered through the ToBuffer, ToString, or CharAt methods (GitHub POC).

Additional resources


SourceThis report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-77415CRITICAL9.3
  • JavaScript logoJavaScript
  • jsonata
NoYesAug 21, 2026
CVE-2026-77414CRITICAL9.3
  • JavaScript logoJavaScript
  • jsonata
NoYesAug 21, 2026
CVE-2026-77413CRITICAL9.3
  • JavaScript logoJavaScript
  • jsonata
NoYesAug 21, 2026
CVE-2026-63421HIGH7.5
  • JavaScript logoJavaScript
  • @keystone-6/core
NoYesAug 21, 2026
CVE-2026-53509MEDIUM5.7
  • JavaScript logoJavaScript
  • @aborruso/ckan-mcp-server
NoYesAug 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management