A vulnerability labeled as problematic has been found in Squirrel up to 3.2. This vulnerability affects the function sqstd_rex_newnode in the library sqstdlib/sqstdrex.cpp. Executing a manipulation can lead to null pointer dereference.

The identification of this vulnerability is CVE-2026-3389. The attack can only be executed locally. Furthermore, there is an exploit available.

The project was informed of the problem early through an issue report but has not responded yet.