PT-2026-22514 · Unknown · Fascinatedbox Lily

Oneafter

·

Published

2026-03-01

·

Updated

2026-04-15

·

CVE-2026-3392

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions FascinatedBox lily versions prior to 2.3
Description A flaw exists in FascinatedBox lily, specifically within the eval tree function of the src/lily emitter.c file, leading to a null pointer dereference. This issue is exploitable locally. The exploit has been publicly released. The project maintainers were notified but have not yet responded.
Recommendations Update to a version of FascinatedBox lily that is newer than 2.3. As a temporary workaround, consider restricting access to the src/lily emitter.c file to minimize the risk of exploitation.

Exploit

Fix

NULL Pointer Dereference

Improper Resource Release

Weakness Enumeration

Related Identifiers

CVE-2026-3392
OPENSUSE-SU-2026:10550-1

Affected Products

Fascinatedbox Lily