PT-2026-20486 · Unknown · Fascinatedbox Lily

Oneafter

·

Published

2026-02-18

·

Updated

2026-02-18

·

CVE-2026-2662

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FascinatedBox lily versions prior to 2.3
Description A flaw exists in FascinatedBox lily, specifically within the count transforms function located in the src/lily emitter.c file. This issue leads to an out-of-bounds read condition. The exploitation of this flaw is limited to local execution. The exploit code has been publicly released. The project maintainers were notified of the issue but have not yet responded.
Recommendations Versions prior to 2.3 should be updated. As a temporary workaround, consider restricting access to the src/lily emitter.c file to minimize the risk of exploitation.

Exploit

Fix

Memory Corruption

Buffer Overflow

Out of bounds Read

Weakness Enumeration

Related Identifiers

CVE-2026-2662

Affected Products

Fascinatedbox Lily