Description
A security flaw has been discovered in FascinatedBox lily up to 2.3. Impacted is the function clear_storages of the file src/lily_emitter.c. The manipulation results in out-of-bounds read. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-03-01
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Assess Impact
AI Analysis

Impact

The flaw resides in the clear_storages routine in lily_emitter.c of the FascinatedBox Lily project up to version 2.3. An attacker with local access can manipulate the function to trigger an out‐of‐bounds read, allowing arbitrary memory contents to be inspected. The vulnerability is classified as CWE‑119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) and CWE‑125 (Out-of-bounds Read). The potential impact is leakage of sensitive data from memory, which can aid further attacks such as credential theft or system compromise.

Affected Systems

The issue affects all installations of FascinatedBox Lily versions 2.3 and earlier. No later sub‑versions are listed as patched, and the repository has no public fix mentioned in the current release data.

Risk and Exploitability

The CVSS v3.1 score is 4.8, indicating a medium risk when considering local access. The EPSS score is less than 1%, suggesting that exploitation likelihood is low at present, although a public exploit has already been made available. The vulnerability is not yet listed in the CISA KEV catalog, which implies no large‑scale exploitation has been reported. The likely attack vector is local, requiring that an adversary already runs code on the host or gains local file access to deploy the exploit.

Generated by OpenCVE AI on April 16, 2026 at 14:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Verify whether your deployed Lily instance is version 2.3 or earlier and confirm it is vulnerable.
  • Check the official GitHub repository (issue #383) for any commits, tags, or releases that address the out-of-bounds read and apply the latest fixed version or patch.
  • If no patch is available, remove or disable Lily from the environment or restrict local access to its executable until a fix is distributed.
  • Stay alert for vendor updates or advisories and apply any official patch as soon as it appears.

Generated by OpenCVE AI on April 16, 2026 at 14:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 04 Mar 2026 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Lily-lang
Lily-lang lily
CPEs cpe:2.3:a:lily-lang:lily:*:*:*:*:*:*:*:*
Vendors & Products Lily-lang
Lily-lang lily

Mon, 02 Mar 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 02 Mar 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Fascinatedbox
Fascinatedbox lily
Vendors & Products Fascinatedbox
Fascinatedbox lily

Sun, 01 Mar 2026 11:45:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in FascinatedBox lily up to 2.3. Impacted is the function clear_storages of the file src/lily_emitter.c. The manipulation results in out-of-bounds read. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Title FascinatedBox lily lily_emitter.c clear_storages out-of-bounds
Weaknesses CWE-119
CWE-125
References
Metrics cvssV2_0

{'score': 1.7, 'vector': 'AV:L/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 3.3, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Fascinatedbox Lily
Lily-lang Lily
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-03-02T18:38:07.796Z

Reserved: 2026-02-28T17:03:49.590Z

Link: CVE-2026-3391

cve-icon Vulnrichment

Updated: 2026-03-02T18:37:58.153Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-01T12:15:59.180

Modified: 2026-04-29T01:00:01.613

Link: CVE-2026-3391

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-16T15:00:14Z

Weaknesses