---
id: CVE-2026-8261
title: A vulnerability was determined in Squirrel up to 3.2
summary: >-
  A vulnerability was determined in Squirrel up to 3.2. This affects the
  function SQFunctionProto::Load of the file squirrel/sqobject.cpp. This
  manipulation causes heap-based buffer overflow. The attack is restricted to
  local execution. Th…
severity: medium
cvss: 5.9
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-119
  - CWE-122
published: '2026-05-11'
updated: '2026-07-23'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-8261'
references:
  - url: 'https://github.com/albertodemichelis/squirrel/issues/326'
    label: cna@vuldb.com
  - url: >-
      https://github.com/biniamf/pocs/tree/main/squirrel-sqobject-functionproto-load-intovf-lineinfos
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/809904'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/362558'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/362558/cti'
    label: cna@vuldb.com
  - url: 'https://github.com/albertodemichelis/squirrel/issues/326'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: 'https://vuldb.com/submit/809904'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00154
epssPercentile: 0.04904
ingestedAt: '2026-07-23T20:19:18.433Z'
---

## Overview

A vulnerability was determined in Squirrel up to 3.2. This affects the function SQFunctionProto::Load of the file squirrel/sqobject.cpp. This manipulation causes heap-based buffer overflow. The attack is restricted to local execution. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
