Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-93751— uri-js through 4.4.1 Improper UTF-8 Decoding via pctDecChars

Quick assessment

Affected
garycourt uri-js
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

uri-js 在 4.4.1 版本之前的所有版本均存在一个不当的 UTF-8 解码漏洞,位于 函数中。该函数会将无效或过长的百分号编码序列错误地解码为 ASCII 元字符。攻击者可以构造特制的百分号编码载荷,从而绕过平台解码器的验证,并注入路径遍历或 CRLF 序列,而下游消费者在处理这些序列时未进行过滤,由此导致安全漏洞。

CVSS 6.5 · Medium

Possible ATT&CK Techniques 1 AI

T1595 · Active Scanning

Affected Version Matrix 1

VendorProduct Version RangeStatus
garycourt uri-js ≤ 4.4.1 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-93751

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
uri-js through 4.4.1 Improper UTF-8 Decoding via pctDecChars
Source: CVE Program / CVE List V5
Vulnerability Description
uri-js through 4.4.1 contains an improper UTF-8 decoding vulnerability in pctDecChars() that decodes invalid and overlong percent-encoded sequences into ASCII metacharacters. Attackers can craft percent-encoded payloads to bypass platform decoder validation and inject path traversal or CRLF sequences that downstream consumers process without filtering.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
Unicode编码处理不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
garycourt uri-js 0 ~ 4.4.1 -

II. Public POCs for CVE-2026-93751

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-93751

登录查看更多情报信息。

Other References for CVE-2026-93751 (4)

IV. Related Vulnerabilities

V. Comments for CVE-2026-93751

No comments yet


Leave a comment