THREATOPS
THREAT OPSThreat News › Escargot v4.3.0-214-gfaee4437 Unauthenticated Remote Debugger Allows Arbitrary JavaScript Evaluation and Local File Disclosure

Escargot v4.3.0-214-gfaee4437 Unauthenticated Remote Debugger Allows Arbitrary JavaScript Evaluation and Local File Disclosure

lowfulldisclosurePublished 2026-08-26

<p>Posted by Ron E on Aug 26</p>An unauthenticated remote debugger vulnerability exists in Escargot<br /> v4.3.0-214-gfaee4437 when the application is compiled with ESCARGOT_DEBUGGER<br /> support and the debug server is enabled using --start-debug-server. The<br /> debugger accepts client connections without authentication or authorization<br /> and provides access to privileged debugger function

MITRE ATT&CK techniques

Original source: https://seclists.org/fulldisclosure/2026/Aug/109