PT-2026-20475 · Wren · Wren

Oneafter

·

Published

2026-02-18

·

Updated

2026-02-18

·

CVE-2026-2657

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions wren-lang wren versions prior to 0.4.0
Description A flaw exists in wren-lang wren that relates to a stack-based buffer overflow. This issue is located within the printError function in the src/vm/wren compiler.c file, part of the Error Message Handler component. The vulnerability can be exploited locally. The details of the exploit have been publicly disclosed. The project maintainers were notified of the issue but have not yet responded.
Recommendations Update to a version of wren-lang wren newer than 0.4.0.

Exploit

Fix

Stack Overflow

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2026-2657

Affected Products

Wren