Loading
A vulnerability was detected in wren-lang wren up to 0.4.0. Affected is the function resolveLocal of the file src/vm/wren_compiler.c. The manipulation results in uncontrolled recursion. Attacking locally is a requirement. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Use CWE-404, Wren vendor hub and Wren product page to widen CVE-2026-3385 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-3387, CVE-2026-3386 and CVE-2026-2858 for nearby disclosures in the same product family.