CVE-2026-2655 describes a use-after-free vulnerability in ChaiScript up to version 6.1.0, specifically within the chaiscript::str_less::operator function in include/chaiscript/chaiscript_defines.hpp. This vulnerability has a CVSS score of 2.5 (LOW), indicating a local attack vector with high complexity and low privileges required, leading to a low impact on availability. While the exploit is publicly available, its exploitability is considered difficult, and there is no evidence of active exploitation, Metasploit modules, or significant community discussion or media coverage. The vendor was notified but has not yet responded.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 6.1.0CPE matchmatch criteria | cpe:2.3:a:chaiscript:chaiscript:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.