Microsoft Security Response Center guidance
Release Notes
Vulnerability intelligence
CVE-2026-97058 and is rated Medium severity with a CVSS score of 5.3. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
Release Notes
sprintf-js through 1.1.3 passes unbounded precision specifiers to toFixed, toExponential, and toPrecision methods without validation, causing uncaught RangeError exceptions. Attackers who control format strings can inject precision values exceeding ECMAScript limits to abort calling operations with minimal payload.