A vulnerability was determined in Squirrel up to 3.2. This vulnerability affects the function sqstd_rex_newnode in the library sqstdlib/sqstdrex.cpp. Executing a manipulation can lead to null pointer dereference. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
References
| Link | Resource |
|---|---|
| https://github.com/albertodemichelis/squirrel/issues/314 | Exploit Issue Tracking Vendor Advisory |
| https://github.com/oneafter/0122/blob/main/i314/repro | Exploit |
| https://vuldb.com/?ctiid.348275 | Permissions Required VDB Entry |
| https://vuldb.com/?id.348275 | Third Party Advisory VDB Entry |
| https://vuldb.com/?submit.761315 | Third Party Advisory VDB Entry |
Configurations
History
05 Mar 2026, 01:42
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:squirrel-lang:squirrel:*:*:*:*:*:*:*:* | |
| First Time |
Squirrel-lang
Squirrel-lang squirrel |
|
| Summary |
|
|
| References | () https://github.com/albertodemichelis/squirrel/issues/314 - Exploit, Issue Tracking, Vendor Advisory | |
| References | () https://github.com/oneafter/0122/blob/main/i314/repro - Exploit | |
| References | () https://vuldb.com/?ctiid.348275 - Permissions Required, VDB Entry | |
| References | () https://vuldb.com/?id.348275 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/?submit.761315 - Third Party Advisory, VDB Entry |
01 Mar 2026, 10:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-01 10:16
Updated : 2026-03-05 01:42
NVD link : CVE-2026-3389
Mitre link : CVE-2026-3389
CVE.ORG link : CVE-2026-3389
JSON object : View
Products Affected
squirrel-lang
- squirrel
