PT-2026-22511 · Squirrel · Squirrel

Oneafter

·

Published

2026-01-01

·

Updated

2026-03-05

·

CVE-2026-3389

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Squirrel versions up to 3.2
Description A flaw exists in Squirrel that can lead to a null pointer dereference. This issue is related to the sqstd rex newnode function within the sqstdlib/sqstdrex.cpp library. The issue can be triggered locally. The exploit has been publicly disclosed.
Recommendations Versions prior to 3.2 should be updated. As a temporary workaround, consider restricting the use of the sqstd rex newnode function until a patch is available.

Exploit

Fix

Improper Resource Release

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

CVE-2026-3389

Affected Products

Squirrel