CVE-2026-2660

LOW

FascinatedBox lily <=2.3 - Use After Free

Title source: llm
STIX 2.1

Description

A vulnerability was identified in FascinatedBox lily up to 2.3. Affected by this issue is the function shorthash_for_name of the file src/lily_symtab.c. The manipulation leads to use after free. Local access is required to approach this attack. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.

References (6)

Core 6
Core References
Permissions Required, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.346458
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.346458
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.753164
Issue Tracking issue-tracking
https://github.com/FascinatedBox/lily/issues/385
Various Sources product
https://github.com/FascinatedBox/lily/

Scores

CVSS v3 3.3
EPSS 0.0001
EPSS Percentile 1.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-119 CWE-416
Status published
Products (1)
lily-lang/lily < 2.3
Published Feb 18, 2026
Tracked Since Feb 18, 2026