CVE-2026-3388
LOWSquirrel up to 3.2 - Memory Corruption
Title source: llmDescription
A vulnerability was found in Squirrel up to 3.2. This affects the function SQCompiler::Factor/SQCompiler::UnaryOP of the file squirrel/sqcompiler.cpp. Performing a manipulation results in uncontrolled recursion. The attack needs to be approached locally. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.
Scores
CVSS v3
3.3
EPSS
0.0002
EPSS Percentile
5.7%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Classification
CWE
CWE-674
CWE-404
Status
published
Affected Products (1)
squirrel-lang/squirrel
< 3.2
Timeline
Published
Mar 01, 2026
Tracked Since
Mar 01, 2026