A security flaw has been discovered in Squirrel up to 3.2. Impacted is the function ReadObject of the file squirrel/sqobject.cpp of the component Cnut File Handler. Performing a manipulation results in heap-based buffer overflow. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Metrics
Affected Vendors & Products
References
History
Tue, 26 May 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security flaw has been discovered in Squirrel up to 3.2. Impacted is the function ReadObject of the file squirrel/sqobject.cpp of the component Cnut File Handler. Performing a manipulation results in heap-based buffer overflow. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. | |
| Title | Squirrel Cnut File sqobject.cpp ReadObject heap-based overflow | |
| First Time appeared |
Squirrel
Squirrel squirrel |
|
| Weaknesses | CWE-119 CWE-122 |
|
| CPEs | cpe:2.3:a:squirrel:squirrel:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Squirrel
Squirrel squirrel |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2026-05-26T11:45:10.180Z
Updated: 2026-05-26T15:18:15.140Z
Reserved: 2026-05-26T05:51:28.774Z
Link: CVE-2026-9541
No data.
Status : Received
Published: 2026-05-26T14:16:46.007
Modified: 2026-05-26T14:16:46.007
Link: CVE-2026-9541
No data.