CVE-2026-45819 PUBLISHED

Assigner: seal
Reserved: 13.05.2026 Published: 13.08.2026 Updated: 13.08.2026

baseline-browser-mapping 2.x before 2.11.0 calls process.exit() instead of throwing on invalid or conflicting input parameters, and can trigger immediate process termination, causing denial of service.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/S:N/AU:Y/R:U/V:D/RE:M/U:Amber
CVSS Score: 6.6

Product Status

Vendor web-platform-dx
Product baseline-browser-mapping
Versions Default: unaffected
  • affected from 2.0.0 to 2.11.0 (excl.)

Credits

  • Seal Security finder

References

Problem Types

  • CWE-705 Incorrect Control Flow Scoping CWE
  • CWE-755 Improper Handling of Exceptional Conditions CWE

Impacts

  • CAPEC-153 Input Data Manipulation: denial of service. The host process exits immediately and the caller cannot recover.