CVE-2026-2858Disclosure(wren / wren)

LOWCVSS 7.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was identified in wren-lang wren up to 0.4.0. This affects the function peekChar of the file src/vm/wren_compiler.c of the component Source File Parser. Such manipulation leads to out-of-bounds read. The attack needs to be performed locally. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-125

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wren

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 1 mentions (2026-02-20); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
wren

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-02-20: 1Mentions · 2026-02-21: 1Mentions · 2026-06-01: 1Technical Details · 2026-02-20: 1Technical Details · 2026-02-21: 1Technical Details · 2026-06-01: 102-2002-2106-01
Signal classification1 categories
Disclosure
3100.0%
Referenced assets5 URLs
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-28586 In multiple functions of http://AppOpsService.java, there is a possible missing permission check due to a permissions bypass. This could lead to local information disclosure… https://www.cve.org/CVERecord?id=CVE-2026-28586 ----- Traducción: CVE-2026-2858… http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑28586, indicating a missing permission check in AppOpsService.java could allow local information disclosure; no exploit, patch, or PoC details are given.

    0000029
    79 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-2858 Local Out-of-Bounds Read Vulnerability in Wren Programming Language Compiler https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-2858

    Post summary

    The entry announces a new CVE (CVE-2026-2858) describing a local out‑of‑bounds read in the Wren compiler, with no evidence of PoC, exploitation, or patch details provided.

    0000028
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2858 A vulnerability was identified in wren-lang wren up to 0.4.0. This affects the function peekChar of the file src/vm/wren_compiler.c of the component Source File Parser.… https://www.cve.org/CVERecord?id=CVE-2026-2858

    Post summary

    The CVE-2026-2858 vulnerability in wren-lang wren up to 0.4.0 impacts the peekChar function in the source file parser, with technical details provided but no mention of exploits, patches, or a PoC.

    0000087
    56.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwrenwren---

Explore more