← Back to CVE List
Vulnerability Intelligence Report
Squirrel sqstdrex.cpp sqstd_rex_newnode null pointer dereference

CVE-2026-3389

A vulnerability was determined in Squirrel up to 3.2. This vulnerability affects the function sqstd_rex_newnode in the library sqstdlib/sqstdrex.cpp. Executing a manipulation can lead to null pointer dereference. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.

No Active Exploit Signals
CVSS Base Score
4.8
MEDIUM
EPSS Probability:0.17%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-476 ↗NULL Pointer Dereference
CWE-404 ↗Denial of Service

Affected Products & Versions

Vendor Product Affected Versions
squirrel-lang squirrel all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.166%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityVulDB · Researcher · Switzerland
Reserved2026-02-28T14:53:46
Published2026-03-01T10:02:07
Last Updated2026-03-02T13:57:10

LINK COPIED TO CLIPBOARD