Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
4.8

janet-lang janet: Local data leak through handleattr function

CVE-2026-2869
Summary

A security issue exists in janet up to version 1.40.1 that could allow an attacker on the same computer to access sensitive data they shouldn't. This issue can be fixed by updating to version 1.41.0. We recommend upgrading the affected component as soon as possible.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
janet-lang janet <= 1.40.1 –
Original title
A vulnerability was identified in janet-lang janet up to 1.40.1. Affected by this vulnerability is the function janetc_varset of the file src/core/specials.c of the component handleattr Handler. Th...
Original description
A vulnerability was identified in janet-lang janet up to 1.40.1. Affected by this vulnerability is the function janetc_varset of the file src/core/specials.c of the component handleattr Handler. The manipulation leads to out-of-bounds read. The attack can only be performed from a local environment. The exploit is publicly available and might be used. Upgrading to version 1.41.0 addresses this issue. The identifier of the patch is 2fabc80151a2b8834ee59cda8a70453f848b40e5. The affected component should be upgraded.
nvd CVSS2.0 1.7
nvd CVSS3.1 5.5
nvd CVSS4.0 4.8
Vulnerability type
CWE-119 Buffer Overflow
CWE-125 Out-of-bounds Read
Published: 21 Feb 2026 · Updated: 12 Mar 2026 · First seen: 6 Mar 2026