CVE-2026-3388

LOW

Squirrel up to 3.2 - Memory Corruption

Title source: llm
STIX 2.1

Description

A vulnerability was found in Squirrel up to 3.2. This affects the function SQCompiler::Factor/SQCompiler::UnaryOP of the file squirrel/sqcompiler.cpp. Performing a manipulation results in uncontrolled recursion. The attack needs to be approached locally. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.

Scores

CVSS v3 3.3
EPSS 0.0003
EPSS Percentile 7.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-404 CWE-674
Status published
Products (1)
squirrel-lang/squirrel < 3.2
Published Mar 01, 2026
Tracked Since Mar 01, 2026