CVE-2026-94448

CVE-2026-94448CVE-2026-94448

Description

When a JavaScript template literal contains consecutive expressions, the context tracking state was not properly reset upon entering a new expression. We now ensure that template-literal expression entries correctly reset context variables so all subsequent regular expression literals are accurately recognized and escaped.

Scoring

Last modified2026-10-08
Sourced from NVD. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.