PT-2026-20482 · Unknown · Fascinatedbox Lily

Oneafter

·

Published

2026-02-18

·

Updated

2026-02-18

·

CVE-2026-2660

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FascinatedBox lily versions prior to 2.3
Description A use-after-free issue exists in the shorthash for name function within the src/lily symtab.c file. Local access is required for exploitation. The project was informed of the issue but has not yet responded. The exploit is publicly available.
Recommendations Update to a version later than 2.3. As a temporary workaround, consider disabling or restricting the use of the shorthash for name function until a patch is available.

Exploit

Fix

Buffer Overflow

Use After Free

Weakness Enumeration

Related Identifiers

CVE-2026-2660

Affected Products

Fascinatedbox Lily