A weakness has been identified in FascinatedBox lily up to 2.3. The affected element is the function eval_tree of the file src/lily_emitter.c. This manipulation causes null pointer dereference. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
References
| Link | Resource |
|---|---|
| https://github.com/FascinatedBox/lily/ | Product |
| https://github.com/FascinatedBox/lily/issues/384 | Exploit Issue Tracking Vendor Advisory |
| https://github.com/oneafter/0122/blob/main/i384/repro.lily | Exploit |
| https://vuldb.com/?ctiid.348278 | Permissions Required VDB Entry |
| https://vuldb.com/?id.348278 | Third Party Advisory VDB Entry |
| https://vuldb.com/?submit.761328 | Third Party Advisory VDB Entry |
Configurations
History
04 Mar 2026, 02:32
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Lily-lang
Lily-lang lily |
|
| CPE | cpe:2.3:a:lily-lang:lily:*:*:*:*:*:*:*:* | |
| References | () https://github.com/FascinatedBox/lily/ - Product | |
| References | () https://github.com/FascinatedBox/lily/issues/384 - Exploit, Issue Tracking, Vendor Advisory | |
| References | () https://github.com/oneafter/0122/blob/main/i384/repro.lily - Exploit | |
| References | () https://vuldb.com/?ctiid.348278 - Permissions Required, VDB Entry | |
| References | () https://vuldb.com/?id.348278 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/?submit.761328 - Third Party Advisory, VDB Entry |
01 Mar 2026, 12:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-01 12:16
Updated : 2026-03-04 02:32
NVD link : CVE-2026-3392
Mitre link : CVE-2026-3392
CVE.ORG link : CVE-2026-3392
JSON object : View
Products Affected
lily-lang
- lily
