CVE-2026-3385

A vulnerability was detected in wren-lang wren up to 0.4.0. Affected is the function resolveLocal of the file src/vm/wren_compiler.c. The manipulation results in uncontrolled recursion. Attacking locally is a requirement. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
References
Link Resource
https://github.com/oneafter/0122/blob/main/i1218/repro Exploit
https://github.com/wren-lang/wren/ Product
https://github.com/wren-lang/wren/issues/1218 Exploit Issue Tracking Vendor Advisory
https://vuldb.com/?ctiid.348271 Permissions Required VDB Entry
https://vuldb.com/?id.348271 Third Party Advisory VDB Entry
https://vuldb.com/?submit.761305 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:wren:wren:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-03-01 09:15

Updated : 2026-03-10 14:24


NVD link : CVE-2026-3385

Mitre link : CVE-2026-3385

CVE.ORG link : CVE-2026-3385


JSON object : View

Products Affected

wren

  • wren
CWE
CWE-404

Improper Resource Shutdown or Release

CWE-674

Uncontrolled Recursion