CVE-2026-3383

A weakness has been identified in ChaiScript up to 6.1.0. This affects the function chaiscript::Boxed_Number::go of the file include/chaiscript/dispatchkit/boxed_number.hpp. Executing a manipulation can lead to divide by zero. The attack requires local access. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Configurations

Configuration 1 (hide)

cpe:2.3:a:chaiscript:chaiscript:*:*:*:*:*:*:*:*

History

05 Mar 2026, 22:30

Type Values Removed Values Added
First Time Chaiscript
Chaiscript chaiscript
CPE cpe:2.3:a:chaiscript:chaiscript:*:*:*:*:*:*:*:*
References () https://github.com/ChaiScript/ChaiScript/ - () https://github.com/ChaiScript/ChaiScript/ - Product
References () https://github.com/ChaiScript/ChaiScript/issues/634 - () https://github.com/ChaiScript/ChaiScript/issues/634 - Issue Tracking
References () https://github.com/ChaiScript/ChaiScript/issues/634#issue-3828234470 - () https://github.com/ChaiScript/ChaiScript/issues/634#issue-3828234470 - Issue Tracking
References () https://vuldb.com/?ctiid.348269 - () https://vuldb.com/?ctiid.348269 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.348269 - () https://vuldb.com/?id.348269 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.761302 - () https://vuldb.com/?submit.761302 - Third Party Advisory, VDB Entry

02 Mar 2026, 20:30

Type Values Removed Values Added
Summary
  • (es) Se ha identificado una debilidad en ChaiScript hasta 6.1.0, la cual afecta a la función chaiscript::Boxed_Number::go del archivo include/chaiscript/dispatchkit/boxed_number.hpp. Su manipulación puede llevar a una división entre cero. El ataque requiere acceso local. El exploit se ha hecho público y podría ser utilizado para ataques. Se informó con antelación del problema al proyecto, a través de un informe de incidencias, pero aún no ha respondido.

01 Mar 2026, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-01 07:15

Updated : 2026-03-05 22:30


NVD link : CVE-2026-3383

Mitre link : CVE-2026-3383

CVE.ORG link : CVE-2026-3383


JSON object : View

Products Affected

chaiscript

  • chaiscript
CWE
CWE-369

Divide By Zero

CWE-404

Improper Resource Shutdown or Release