← back
CVE-2026-2858

wren-lang wren Source File wren_compiler.c peekChar out-of-bounds

CVSS 4.8 MEDIUMEPSS 0.1%CWE-119CWE-125
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 4.8EPSS 0.1%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
20 Feb 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A vulnerability was identified in wren-lang wren up to 0.4.0. This affects the function peekChar of the file src/vm/wren_compiler.c of the component Source File Parser. Such manipulation leads to out-of-bounds read. The attack needs to be performed locally. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P
Affected products
wren-lang · wren

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →