PT-2026-20486 · Unknown · Fascinatedbox Lily
Oneafter
·
Published
2026-02-18
·
Updated
2026-02-18
·
CVE-2026-2662
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FascinatedBox lily versions prior to 2.3
Description
A flaw exists in FascinatedBox lily, specifically within the
count transforms function located in the src/lily emitter.c file. This issue leads to an out-of-bounds read condition. The exploitation of this flaw is limited to local execution. The exploit code has been publicly released. The project maintainers were notified of the issue but have not yet responded.Recommendations
Versions prior to 2.3 should be updated. As a temporary workaround, consider restricting access to the
src/lily emitter.c file to minimize the risk of exploitation.Exploit
Fix
Memory Corruption
Buffer Overflow
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Fascinatedbox Lily