3.3 LOW
- CVSS version: 3.1
- Attack vector (AV):
- Attack complexity (AC):
- Privileges required (PR):
- User interaction (UI):
- Scope (S):
- Confidentiality impact (C):
- Integrity impact (I):
- Availability impact (A):
wren-lang wren Source File wren_compiler.c peekChar out-of-bounds
A vulnerability was identified in wren-lang wren up to 0.4.0. This affects the function peekChar of the file src/vm/wren_compiler.c of the component Source File Parser. Such manipulation leads to out-of-bounds read. The attack needs to be performed locally. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
References
- VDB-347097 | wren-lang wren Source File wren_compiler.c peekChar out-of-bounds vdb-entry technical-description
- VDB-347097 | CTI Indicators (IOB, IOC, IOA) signature permissions-required
- Submit #754489 | wren-lang wren main-branch Heap-based Buffer Overflow third-party-advisory
- https://github.com/wren-lang/wren/issues/1217 issue-tracking
- https://github.com/oneafter/0122/blob/main/i1217/repro exploit
- https://github.com/wren-lang/wren/ product
Affected products
- ==0.3
- ==0.2
- ==0.1
- ==0.4.0
Matching in nixpkgs
pkgs.fairywren
FairyWren Icon Set
-
nixos-unstable 0-unstable-2026-02-08
- nixpkgs-unstable 0-unstable-2026-02-08
- nixos-unstable-small 0-unstable-2026-02-08
-
nixos-25.11 0-unstable-2024-06-10
- nixos-25.11-small 0-unstable-2024-06-10
- nixpkgs-25.11-darwin 0-unstable-2024-06-10
pkgs.tree-sitter-grammars.tree-sitter-wren
Tree-sitter grammar for wren
-
nixos-unstable 0-unstable-2024-01-01
- nixos-unstable-small 0-unstable-2024-01-01
pkgs.python313Packages.tree-sitter-grammars.tree-sitter-wren
Python bindings for tree-sitter-wren
-
nixos-unstable 0+unstable20240101
- nixos-unstable-small 0+unstable20240101
pkgs.python314Packages.tree-sitter-grammars.tree-sitter-wren
Python bindings for tree-sitter-wren
-
nixos-unstable 0+unstable20240101
- nixos-unstable-small 0+unstable20240101
Package maintainers
-
@D3vil0p3r Antonio Voza <vozaanthony@gmail.com>
-
@stepbrobd Yifei Sun <ysun@hey.com>
-
@adfaure Adrien Faure <adfaure@pm.me>
-
@A-jay98 Ali Jamadi <ali@jamadi.me>
-
@mightyiam Shahar "Dawn" Or <mightyiampresence@gmail.com>
-
@aciceri Andrea Ciceri <andrea.ciceri@autistici.org>