CVE-2026-3385

A vulnerability was detected in wren-lang wren up to 0.4.0. Affected is the function resolveLocal of the file src/vm/wren_compiler.c. The manipulation results in uncontrolled recursion. Attacking locally is a requirement. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
References
Link Resource
https://github.com/oneafter/0122/blob/main/i1218/repro Exploit
https://github.com/wren-lang/wren/ Product
https://github.com/wren-lang/wren/issues/1218 Exploit Issue Tracking Vendor Advisory
https://vuldb.com/?ctiid.348271 Permissions Required VDB Entry
https://vuldb.com/?id.348271 Third Party Advisory VDB Entry
https://vuldb.com/?submit.761305 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:wren:wren:*:*:*:*:*:*:*:*

History

10 Mar 2026, 14:24

Type Values Removed Values Added
First Time Wren wren
Wren
CPE cpe:2.3:a:wren:wren:*:*:*:*:*:*:*:*
References () https://github.com/oneafter/0122/blob/main/i1218/repro - () https://github.com/oneafter/0122/blob/main/i1218/repro - Exploit
References () https://github.com/wren-lang/wren/ - () https://github.com/wren-lang/wren/ - Product
References () https://github.com/wren-lang/wren/issues/1218 - () https://github.com/wren-lang/wren/issues/1218 - Exploit, Issue Tracking, Vendor Advisory
References () https://vuldb.com/?ctiid.348271 - () https://vuldb.com/?ctiid.348271 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.348271 - () https://vuldb.com/?id.348271 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.761305 - () https://vuldb.com/?submit.761305 - Third Party Advisory, VDB Entry
Summary
  • (es) Se ha encontrado una vulnerabilidad en wren-lang wren hasta 0.4.0, la cual afecta a la función resolveLocal del archivo src/vm/wren_compiler.c. Su manipulación resulta en recursión incontrolada. Es necesario realizar el ataque en local. El exploit es ahora público y puede ser usado. Se informó con antelación del problema al proyecto, a través de un informe de incidencias, pero aún no ha respondido.

01 Mar 2026, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-01 09:15

Updated : 2026-03-10 14:24


NVD link : CVE-2026-3385

Mitre link : CVE-2026-3385

CVE.ORG link : CVE-2026-3385


JSON object : View

Products Affected

wren

  • wren
CWE
CWE-404

Improper Resource Shutdown or Release

CWE-674

Uncontrolled Recursion