CVE-2026-24827 Details
Description
Out-of-bounds Write vulnerability in gerstrong Commander-Genius.This issue affects Commander-Genius: before Release refs/pull/358/merge.
A vulnerability allowing out-of-bounds write has been identified in Commander-Genius, specifically in versions prior to the release that includes pull request 358. This issue arises from the handling of Lua code in the GsKit library, where certain files were cloned from the official Lua repository but did not incorporate a critical security patch. As a result, the vulnerability could potentially be exploited by manipulating the Lua debugging or virtual machine components within the application.
Users can update to the latest version of Commander-Genius, which includes the necessary security patch. Instructions for downloading the latest version are available on the Commander-Genius GitHub repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jan 27, 2026CISA-ADP
Assessed Jan 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/gerstrong/Commander-Genius/pull/379 | [email protected] | Issue TrackingVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-787 | Out-of-bounds Write | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| gerstrong Commander-Genius | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 27, 2026 | New CVE Received | [email protected] |
Volerion