← Vulnerability feed

Vulnerability record · CVE-2025-65570 · published 29 December 2025

CVE-2025-65570: Jsish type confusion vulnerability

Jsish · Jsish

A type confusion in jsish 2.0 allows incorrect control flow during execution of the OP_NEXT opcode. When an “instanceof” expression uses an array element access as the left-hand operand inside a for-in loop, the instructions implementation leaves an additional array reference on the stack rather than consuming it during OP_INSTANCEOF. As a result, OP_NEXT interprets the array as an iterator object and reads the iterCmd function pointer from an invalid structure, potentially causing a crash or enabling code execution depending on heap layout.

9.8 CVSS 3.1 Critical EPSS 0.53% · top 57.6% CWE-843 · Type confusion
9.8CVSS 3.1 base score
0.53%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A type confusion in jsish 2.0 allows incorrect control flow during execution of the OP_NEXT opcode. When an “instanceof” expression uses an array element access as the left-hand operand inside a for-in loop, the instructions implementation leaves an additional array reference on the stack rather than consuming it during OP_INSTANCEOF. As a result, OP_NEXT interprets the array as an iterator object and reads the iterCmd function pointer from an invalid structure, potentially causing a crash or enabling code execution depending on heap layout.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-65570 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-24186Jsish out-of-bounds write vulnerabilityJsish v3.5.0 (commit 42c694c) was discovered to contain a stack-overflow via the component IterGetKeysCallback at /jsish/src/jsiValue.c.EPSS 0.88%9.8CVE-2024-24188Jsish out-of-bounds write vulnerabilityJsish v3.5.0 was discovered to contain a heap-buffer-overflow in ./src/jsiUtils.c.EPSS 0.80%9.8CVE-2024-24189Jsish use after free vulnerabilityJsish v3.5.0 (commit 42c694c) was discovered to contain a use-after-free via the SplitChar at ./src/jsiUtils.c.EPSS 0.69%9.8CVE-2020-22873Jsish classic buffer overflow vulnerabilityBuffer overflow vulnerability in function NumberToPrecisionCmd in jsish before 3.0.7, allows remote attackers to execute arbitrary code.EPSS 2.3%9.8CVE-2020-22874Jsish integer overflow vulnerabilityInteger overflow vulnerability in function Jsi_ObjArraySizer in jsish before 3.0.8, allows remote attackers to execute arbitrary code.EPSS 3.3%9.8CVE-2020-22875Jsish integer overflow vulnerabilityInteger overflow vulnerability in function Jsi_ObjSetLength in jsish before 3.0.6, allows remote attackers to execute arbitrary code.EPSS 3.3%9.8CVE-2019-1010177Jsish use after free vulnerabilityJsish 2.4.70 2.047 is affected by: Use After Free. The impact is: denial of service and possibly arbitrary code execution. The component is: function…EPSS 2.1%7.8CVE-2021-46482Jsish out-of-bounds write vulnerabilityJsish v3.5.0 was discovered to contain a heap buffer overflow via NumberConstructor at src/jsiNumber.c.EPSS 0.84%

Source: NIST National Vulnerability Database (record CVE-2025-65570), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.