Description
A weakness has been identified in ChaiScript up to 6.1.0. This affects the function chaiscript::Boxed_Number::go of the file include/chaiscript/dispatchkit/boxed_number.hpp. Executing a manipulation can lead to divide by zero. The attack requires local access. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Problem types
Timeline
| 2026-02-28: | Advisory disclosed |
| 2026-02-28: | VulDB entry created |
| 2026-02-28: | VulDB entry last update |
Credits
Oneafter (VulDB User)
References
vuldb.com/?id.348269 (VDB-348269 | ChaiScript boxed_number.hpp go divide by zero)
vuldb.com/?ctiid.348269 (VDB-348269 | CTI Indicators (IOB, IOC, IOA))
vuldb.com/?submit.761302 (Submit #761302 | ChaiScript develop branch Divide By Zero)
github.com/ChaiScript/ChaiScript/issues/634
github.com/ChaiScript/ChaiScript/issues/634
github.com/ChaiScript/ChaiScript/