CVE-2026-2661

A security flaw has been discovered in Squirrel up to 3.2. This affects the function SQObjectPtr::operator in the library squirrel/sqobject.h. The manipulation results in heap-based buffer overflow. The attack needs to be approached locally. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
References
Link Resource
https://github.com/albertodemichelis/squirrel/issues/310 Exploit Issue Tracking
https://github.com/oneafter/0122/blob/main/i310/repro Exploit
https://vuldb.com/?ctiid.346459 Permissions Required VDB Entry
https://vuldb.com/?id.346459 Third Party Advisory VDB Entry
https://vuldb.com/?submit.753165 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:squirrel-lang:squirrel:*:*:*:*:*:*:*:*

History

20 Feb 2026, 20:04

Type Values Removed Values Added
CPE cpe:2.3:a:squirrel-lang:squirrel:*:*:*:*:*:*:*:*
First Time Squirrel-lang
Squirrel-lang squirrel
References () https://github.com/albertodemichelis/squirrel/issues/310 - () https://github.com/albertodemichelis/squirrel/issues/310 - Exploit, Issue Tracking
References () https://github.com/oneafter/0122/blob/main/i310/repro - () https://github.com/oneafter/0122/blob/main/i310/repro - Exploit
References () https://vuldb.com/?ctiid.346459 - () https://vuldb.com/?ctiid.346459 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.346459 - () https://vuldb.com/?id.346459 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.753165 - () https://vuldb.com/?submit.753165 - Third Party Advisory, VDB Entry
Summary
  • (es) Se ha descubierto una falla de seguridad en Squirrel hasta 3.2. Esto afecta a la función SQObjectPtr::operator en la biblioteca squirrel/sqobject.h. Su manipulación resulta en un desbordamiento de búfer basado en montículo. El ataque necesita ser abordado localmente. El exploit ha sido liberado al público y puede ser utilizado para ataques. Se informó pronto al proyecto del problema a través de un informe de incidencias, pero no ha respondido aún.

18 Feb 2026, 20:18

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-18 20:18

Updated : 2026-02-20 20:04


NVD link : CVE-2026-2661

Mitre link : CVE-2026-2661

CVE.ORG link : CVE-2026-2661


JSON object : View

Products Affected

squirrel-lang

  • squirrel
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-122

Heap-based Buffer Overflow