A security flaw has been discovered in FascinatedBox lily up to 2.3. Impacted is the function clear_storages of the file src/lily_emitter.c. The manipulation results in out-of-bounds read. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
References
| Link | Resource |
|---|---|
| https://github.com/FascinatedBox/lily/ | Product |
| https://github.com/FascinatedBox/lily/issues/383 | Exploit Issue Tracking Vendor Advisory |
| https://github.com/oneafter/0122/blob/main/i383/repro.lily | Exploit |
| https://vuldb.com/?ctiid.348277 | Permissions Required VDB Entry |
| https://vuldb.com/?id.348277 | Third Party Advisory VDB Entry |
| https://vuldb.com/?submit.761327 | Third Party Advisory VDB Entry |
Configurations
History
04 Mar 2026, 02:43
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Lily-lang
Lily-lang lily |
|
| CPE | cpe:2.3:a:lily-lang:lily:*:*:*:*:*:*:*:* | |
| References | () https://github.com/FascinatedBox/lily/ - Product | |
| References | () https://github.com/FascinatedBox/lily/issues/383 - Exploit, Issue Tracking, Vendor Advisory | |
| References | () https://github.com/oneafter/0122/blob/main/i383/repro.lily - Exploit | |
| References | () https://vuldb.com/?ctiid.348277 - Permissions Required, VDB Entry | |
| References | () https://vuldb.com/?id.348277 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/?submit.761327 - Third Party Advisory, VDB Entry |
01 Mar 2026, 12:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-01 12:15
Updated : 2026-03-04 02:43
NVD link : CVE-2026-3391
Mitre link : CVE-2026-3391
CVE.ORG link : CVE-2026-3391
JSON object : View
Products Affected
lily-lang
- lily
