Impact
connorskees grass contains an unchecked error condition in its UTF‑8 Character Handler, specifically the grass_compiler::raw_to_parse_error function. Malformed UTF‑8 input triggers an error that causes the compiler to terminate prematurely, resulting in a service crash and a denial of service. The flaw does not affect confidentiality or integrity and is limited to the local execution context.
Affected Systems
connorskees Grass releases up to and including version 0.13.4 are affected. Any installation that exposes the grass compiler to local input is vulnerable; newer releases are not impacted by this specific issue.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate severity, and the EPSS score of <1% suggests a very low probability of exploitation. The vulnerability is limited to local code execution or the ability to supply crafted input on the host, so remote attackers are not directly affected. An exploit has been published, but the issue is not listed in the CISA KEV catalog.
OpenCVE Enrichment