VulnerabilityAnalyzed
CVE-2026-2858
A vulnerability was identified in wren-lang wren up to 0.4.0.
LOW 1.9EPSS 0.12%
Does this matter?
Lower severity and a low EPSS score (0.12%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability was identified in wren-lang wren up to 0.4.0. This affects the function peekChar of the file src/vm/wren_compiler.c of the component Source File Parser. Such manipulation leads to out-of-bounds read. The attack needs to be performed locally. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
- CVSS 4.0
- 1.9 LOWCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.12% probability · 2th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119, CWE-125
- Affected
- wren/wren
- Source
- cna@vuldb.com
References
- https://github.com/oneafter/0122/blob/main/i1217/reproIssue Tracking, Product
- https://github.com/wren-lang/wren/Product
- https://github.com/wren-lang/wren/issues/1217Issue Tracking
- https://vuldb.com/?ctiid.347097Permissions Required, VDB Entry
- https://vuldb.com/?id.347097Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.754489Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.