CVE-2026-3385 MEDIUM

CVE-2026-3385: wren-lang wren wren_compiler.c resolveLocal recursion

Vendor Wren-Lang
Product wren
Weakness CWE-674
Published March 1, 2026
Last update March 2, 2026

CVSS base score

4.8/10
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P

What the vulnerability does

01Description

A vulnerability was detected in wren-lang wren up to 0.4.0. Affected is the function resolveLocal of the file src/vm/wren_compiler.c. The manipulation results in uncontrolled recursion. Attacking locally is a requirement. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Key dates

02Disclosure timeline

March 1, 2026 CVE published
March 2, 2026 Record updated