PT-2026-4896 · Turanszkij · Wickedengine

Titan Team

·

Published

2026-01-27

·

Updated

2026-03-05

·

CVE-2026-24821

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:H/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:U/V:D/RE:M/U:Amber
Name of the Vulnerable Software and Affected Versions turanszkij WickedEngine versions through 0.71.727
Description An out-of-bounds read issue exists in turanszkij WickedEngine, specifically within the LUA modules and associated file lparser.C. The issue is a heap-based buffer over-read that can occur when compiling untrusted Lua code. This allows attackers to potentially bypass memory boundaries.
Recommendations Versions prior to 0.71.728 are affected. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Out of bounds Read

Weakness Enumeration

Related Identifiers

CVE-2026-24821

Affected Products

Wickedengine