Aller au contenu

Fiche vulnérabilité

CVE-2026-3386 : faille élevée wren wren (CVSS 7.1)

Description

A flaw has been found in wren-lang wren up to 0.4.0. Affected by this vulnerability is the function emitOp of the file src/vm/wren_compiler.c. This manipulation causes out-of-bounds read. It is possible to launch the attack on the local host. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.

En bref

Sévérité
Élevée (CVSS 7.1)
Vecteur CVSS
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Exploitation active
Non signalée par la CISA
Publication
1 mars 2026
Dernière mise à jour
17 juin 2026

Produits concernés

  • wren wren

Références

Rechercher une autre vulnérabilité dans la base CVE