THREAT OPS › Threat News › Escargot v4.3.0-214-gfaee4437 Unauthenticated Remote Debugger Allows Arbitrary JavaScript Evaluation and Local File Disclosure
Escargot v4.3.0-214-gfaee4437 Unauthenticated Remote Debugger Allows Arbitrary JavaScript Evaluation and Local File Disclosure
<p>Posted by Ron E on Aug 26</p>An unauthenticated remote debugger vulnerability exists in Escargot<br /> v4.3.0-214-gfaee4437 when the application is compiled with ESCARGOT_DEBUGGER<br /> support and the debug server is enabled using --start-debug-server. The<br /> debugger accepts client connections without authentication or authorization<br /> and provides access to privileged debugger function
MITRE ATT&CK techniques
- JavaScriptT1059.007
Original source: https://seclists.org/fulldisclosure/2026/Aug/109