Untriaged
Permalink
CVE-2026-2858
3.3 LOW
- CVSS version: 3.1
- Attack vector (AV):
- Attack complexity (AC):
- Privileges required (PR):
- User interaction (UI):
- Scope (S):
- Confidentiality impact (C):
- Integrity impact (I):
- Availability impact (A):
Activity log
- Created suggestion
wren-lang wren Source File wren_compiler.c peekChar out-of-bounds
A vulnerability was identified in wren-lang wren up to 0.4.0. This affects the function peekChar of the file src/vm/wren_compiler.c of the component Source File Parser. Such manipulation leads to out-of-bounds read. The attack needs to be performed locally. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
References
-
VDB-347097 | wren-lang wren Source File wren_compiler.c peekChar out-of-bounds vdb-entrytechnical-description
-
-
Submit #754489 | wren-lang wren main-branch Heap-based Buffer Overflow third-party-advisory
-
https://github.com/wren-lang/wren/issues/1217 issue-tracking
Affected products
wren
- ==0.4.0
- ==0.3
- ==0.1
- ==0.2
Matching in nixpkgs
pkgs.fairywren
FairyWren Icon Set
-
nixos-unstable 0-unstable-2026-02-08
- nixpkgs-unstable 0-unstable-2026-02-08
- nixos-unstable-small 0-unstable-2026-02-08
-
nixos-25.11 0-unstable-2024-06-10
- nixos-25.11-small 0-unstable-2024-06-10
- nixpkgs-25.11-darwin 0-unstable-2024-06-10
pkgs.tree-sitter-grammars.tree-sitter-wren
Tree-sitter grammar for wren
-
nixos-unstable -
- nixos-unstable-small 0-unstable-2024-01-01
pkgs.python313Packages.tree-sitter-grammars.tree-sitter-wren
Python bindings for tree-sitter-wren
-
nixos-unstable -
- nixos-unstable-small 0+unstable20240101
pkgs.python314Packages.tree-sitter-grammars.tree-sitter-wren
Python bindings for tree-sitter-wren
-
nixos-unstable -
- nixos-unstable-small 0+unstable20240101
Package maintainers
-
@D3vil0p3r Antonio Voza <vozaanthony@gmail.com>
-
@A-jay98 Ali Jamadi <ali@jamadi.me>
-
@stepbrobd Yifei Sun <ysun@hey.com>
-
@mightyiam Shahar "Dawn" Or <mightyiampresence@gmail.com>
-
@adfaure Adrien Faure <adfaure@pm.me>
-
@aciceri Andrea Ciceri <andrea.ciceri@autistici.org>