PT-2026-21304 · Wren · Wren
Oneafter
·
Published
2026-02-20
·
Updated
2026-02-20
·
CVE-2026-2858
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
wren-lang wren versions prior to 0.4.0
Description
A flaw exists in wren-lang wren that allows for an out-of-bounds read. This issue is related to the
peekChar function within the src/vm/wren compiler.c file, specifically in the Source File Parser component. The attack requires local access. The project was notified of the issue but has not yet responded. The exploit is publicly available.Recommendations
Update to a version of wren-lang wren newer than 0.4.0.
Exploit
Fix
Buffer Overflow
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wren