CVE-2026-3390Disclosure(lily-lang / lily)

LOWCVSS 5.5 · MEDIUM

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was identified in FascinatedBox lily up to 2.3. This issue affects the function patch_line_end of the file src/lily_build_error.c of the component Error Reporting. The manipulation leads to out-of-bounds read. The attack can only be performed from a local environment. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-125

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • lily

Threat summary

  • 4 mentions across 1 observed day

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • 4 total mentions across 1 day

Affected systems

Vendors
Products
lily

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-03-01: 4Technical Details · 2026-03-01: 403-01
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Full discourse4 posts
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-3390 - FascinatedBox lily Error Reporting lily_build_error.c patch_line_end out-of-bounds Intel Report: https://ift.tt/eOZrzqx

    Post summary

    The alert announces CVE-2026-3390, an out-of-bounds vulnerability in FascinatedBox's lily_build_error.c, and provides a link to an Intel report.

    0000043
    343 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-3390 A vulnerability was identified in FascinatedBox lily up to 2.3. This issue affects the function patch_line_end of the file src/lily_build_error.c of the component Error… https://www.cve.org/CVERecord?id=CVE-2026-3390 ----- Traducción: CVE-2026-3390 Se … http://infoflow.cloud`

    Post summary

    The post announces the disclosure of CVE-2026-3390, detailing the affected function and file in FascinatedBox lily up to version 2.3.

    0000042
    55 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3390 A vulnerability was identified in FascinatedBox lily up to 2.3. This issue affects the function patch_line_end of the file src/lily_build_error.c of the component Error… https://www.cve.org/CVERecord?id=CVE-2026-3390

    Post summary

    A new CVE-2026-3390 vulnerability was disclosed affecting FascinatedBox lily up to version 2.3, specifically the patch_line_end function in src/lily_build_error.c of the Error component.

    00000415
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3390 Local Out-of-Bounds Read Vulnerability in FascinatedBox Lily Up to 2.3 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3390

    Post summary

    The text announces CVE-2026-3390, a local out-of-bounds read vulnerability in FascinatedBox Lily up to version 2.3, without providing exploitation details or mitigation information.

    0000047
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applily-langlily---

Explore more