VYPR

Squirrelly

by Squirrelly

Source repositories

CVEs (9)

  • CVE-2024-40453CriAug 21, 2024
    risk 0.57cvss 9.8epss 0.01

    squirrellyjs squirrelly v9.0.0 and fixed in v.9.0.1 was discovered to contain a code injection vulnerability via the component options.varName.

  • CVE-2021-32819HigMay 14, 2021
    risk 0.50cvss 8.0epss 0.60

    Squirrelly is a template engine implemented in JavaScript that works out of the box with ExpressJS. Squirrelly mixes pure template data with engine configuration options through the Express render API. By overwriting internal configuration options remote code execution may be…

  • CVE-2026-8261MedMay 11, 2026
    risk 0.38cvss 5.9epss 0.00

    A vulnerability was determined in Squirrel up to 3.2. This affects the function SQFunctionProto::Load of the file squirrel/sqobject.cpp. This manipulation causes heap-based buffer overflow. The attack is restricted to local execution. The exploit has been publicly disclosed and…

  • CVE-2026-9541MedMay 26, 2026
    risk 0.34cvss 5.3epss 0.00

    A security flaw has been discovered in Squirrel up to 3.2. Impacted is the function ReadObject of the file squirrel/sqobject.cpp of the component Cnut File Handler. Performing a manipulation results in heap-based buffer overflow. The attack is only possible with local access.…

  • CVE-2026-8258MedMay 11, 2026
    risk 0.34cvss 5.3epss 0.00

    A flaw has been found in Squirrel up to 3.2. Impacted is the function validate_format in the library sqstdlib/sqstdstring.cpp. Executing a manipulation can lead to stack-based buffer overflow. The attack can only be executed locally. The exploit has been published and may be…

  • CVE-2026-3389LowMar 1, 2026
    risk 0.21cvss 3.3epss 0.00

    A vulnerability was determined in Squirrel up to 3.2. This vulnerability affects the function sqstd_rex_newnode in the library sqstdlib/sqstdrex.cpp. Executing a manipulation can lead to null pointer dereference. The attack can only be executed locally. The exploit has been…

  • CVE-2026-3388LowMar 1, 2026
    risk 0.21cvss 3.3epss 0.00

    A vulnerability was found in Squirrel up to 3.2. This affects the function SQCompiler::Factor/SQCompiler::UnaryOP of the file squirrel/sqcompiler.cpp. Performing a manipulation results in uncontrolled recursion. The attack needs to be approached locally. The exploit has been…

  • CVE-2026-2661LowFeb 18, 2026
    risk 0.21cvss 3.3epss 0.00

    A security flaw has been discovered in Squirrel up to 3.2. This affects the function SQObjectPtr::operator in the library squirrel/sqobject.h. The manipulation results in heap-based buffer overflow. The attack needs to be approached locally. The exploit has been released to the…

  • CVE-2026-2659LowFeb 18, 2026
    risk 0.21cvss 3.3epss 0.00

    A vulnerability was determined in Squirrel up to 3.2. Affected by this vulnerability is the function SQFuncState::PopTarget of the file src/squirrel/squirrel/sqfuncstate.cpp. Executing a manipulation of the argument _target_stack can lead to out-of-bounds read. It is possible to…