Impact
The flaw is a reachable assertion (CWE-617) that can be triggered in the analyze_struct function of flatcc’s compiler component. Triggering the assertion can cause the compiler to fail, and the issue permits a remote attack with publicly available exploits.
Affected Systems
The vulnerability affects Dvidelabs flatcc versions up to and including 0.6.3. The issue is located in src/compiler/semantics.c of the Struct Analysis component.
Risk and Exploitability
CVSS 6.9 denotes moderate severity, and the EPSS score is not available, making exploitation likelihood uncertain. The vulnerability is not listed in the CISA KEV catalog. Attack requires remote access to the compiler environment, and the public proof‑of‑concept demonstrates that the exploit is publicly available. Because the flaw is an assertion, it may result in a a crash is not indicated by the current description.
OpenCVE Enrichment