Junglewise Threat Intelligence

CVE-2026-93749: source-map-js unvalidated offset line in indexed source maps

CVE-2026-93749 · Severity: high · CVSS 7.5 · Published 2026-09-18

Executive brief

source-map-js is a JavaScript library used to consume and generate source maps, which are used during software development to map minified code back to original source. A flaw in how the library validates indexed source maps allows attackers to supply extremely large offset line values that cause the application to freeze and become unresponsive for extended periods, denying service to legitimate users.

Technical details

The vulnerability exists in source-map-js versions through 1.2.1, which fail to validate per-section offset line values in indexed source maps. An attacker can craft a malicious source map file with arbitrarily large numeric offset values that trigger synchronous event loop blocking in Node.js environments. This results in denial of service where the affected application cannot process other requests while the blocking operation completes.

Affected products

  • 7rulnik source-map-js through 1.2.1

Timeline

  • 2026-09-18: disclosed

References