CVE-2026-3391

A security flaw has been discovered in FascinatedBox lily up to 2.3. Impacted is the function clear_storages of the file src/lily_emitter.c. The manipulation results in out-of-bounds read. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
References
Link Resource
https://github.com/FascinatedBox/lily/ Product
https://github.com/FascinatedBox/lily/issues/383 Exploit Issue Tracking Vendor Advisory
https://github.com/oneafter/0122/blob/main/i383/repro.lily Exploit
https://vuldb.com/?ctiid.348277 Permissions Required VDB Entry
https://vuldb.com/?id.348277 Third Party Advisory VDB Entry
https://vuldb.com/?submit.761327 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:lily-lang:lily:*:*:*:*:*:*:*:*

History

04 Mar 2026, 02:43

Type Values Removed Values Added
First Time Lily-lang
Lily-lang lily
CPE cpe:2.3:a:lily-lang:lily:*:*:*:*:*:*:*:*
References () https://github.com/FascinatedBox/lily/ - () https://github.com/FascinatedBox/lily/ - Product
References () https://github.com/FascinatedBox/lily/issues/383 - () https://github.com/FascinatedBox/lily/issues/383 - Exploit, Issue Tracking, Vendor Advisory
References () https://github.com/oneafter/0122/blob/main/i383/repro.lily - () https://github.com/oneafter/0122/blob/main/i383/repro.lily - Exploit
References () https://vuldb.com/?ctiid.348277 - () https://vuldb.com/?ctiid.348277 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.348277 - () https://vuldb.com/?id.348277 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.761327 - () https://vuldb.com/?submit.761327 - Third Party Advisory, VDB Entry

01 Mar 2026, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-01 12:15

Updated : 2026-03-04 02:43


NVD link : CVE-2026-3391

Mitre link : CVE-2026-3391

CVE.ORG link : CVE-2026-3391


JSON object : View

Products Affected

lily-lang

  • lily
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-125

Out-of-bounds Read