CVE-2026-2656 is a use-after-free vulnerability affecting ChaiScript versions up to 6.1.0, specifically within the chaiscript::Type_Info::bare_equal function. This flaw has a low severity CVSS score of 2.5, requiring local access with high attack complexity and difficult exploitability, leading to a potential low impact on availability. While an exploit has been published, there are no known Metasploit or Nuclei modules, and it is not listed in ExploitDB. The vulnerability has garnered minimal community discussion and media coverage, and is not currently on the CISA KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 6.1.0CPE matchmatch criteria | cpe:2.3:a:chaiscript:chaiscript:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.