Impact
This vulnerability resides in the shorthash_for_name function of lily's symbol table module. A fault in memory handling results in a use‑after‑free condition when a maliciously crafted name is processed. The flaw may cause arbitrary read or write of memory, potentially enabling execution of code with the privileges of the running process. The associated weaknesses are CWE‑119 and CWE‑416.
Affected Systems
Vendors: FascinatedBox. Product: lily. Affected versions: up to 2.3.
Risk and Exploitability
The CVSS base score is 4.8, indicating moderate severity. EPSS is less than 1 %, showing a low probability of exploitation, yet a public exploit is available. The attack requires local access to the lily interpreter, so the risk is confined to machines where a local attacker can run the vulnerable code. There is no KEV listing.
OpenCVE Enrichment