CVE-2026-2659 | Squirrel up to 3.2 sqfuncstate.cpp SQFuncState::PopTarget _target_stack out-of-bounds (Issue 311 / Nessus ID 299488)
A vulnerability described as problematic has been identified in Squirrel up to 3.2. Affected by this vulnerability is the function SQFuncState::PopTarget of the file src/squirrel/squirrel/sqfuncstate.cpp. Executing a manipulation of the argument _target_stack can lead to out-of-bounds read.
This vulnerability is handled as CVE-2026-2659. It is possible to launch the attack on the local host. Additionally, an exploit exists.
The project was informed of the problem early through an issue report but has not responded yet.