A security flaw has been discovered in Squirrel up to 3.2. This affects the function SQObjectPtr::operator in the library squirrel/sqobject.h. The manipulation results in heap-based buffer overflow. The attack needs to be approached locally. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
References
| Link | Resource |
|---|---|
| https://github.com/albertodemichelis/squirrel/issues/310 | Exploit Issue Tracking |
| https://github.com/oneafter/0122/blob/main/i310/repro | Exploit |
| https://vuldb.com/?ctiid.346459 | Permissions Required VDB Entry |
| https://vuldb.com/?id.346459 | Third Party Advisory VDB Entry |
| https://vuldb.com/?submit.753165 | Third Party Advisory VDB Entry |
Configurations
History
20 Feb 2026, 20:04
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:squirrel-lang:squirrel:*:*:*:*:*:*:*:* | |
| First Time |
Squirrel-lang
Squirrel-lang squirrel |
|
| References | () https://github.com/albertodemichelis/squirrel/issues/310 - Exploit, Issue Tracking | |
| References | () https://github.com/oneafter/0122/blob/main/i310/repro - Exploit | |
| References | () https://vuldb.com/?ctiid.346459 - Permissions Required, VDB Entry | |
| References | () https://vuldb.com/?id.346459 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/?submit.753165 - Third Party Advisory, VDB Entry | |
| Summary |
|
18 Feb 2026, 20:18
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-18 20:18
Updated : 2026-02-20 20:04
NVD link : CVE-2026-2661
Mitre link : CVE-2026-2661
CVE.ORG link : CVE-2026-2661
JSON object : View
Products Affected
squirrel-lang
- squirrel
