Pepper Language Heap Buffer Overflow

HIGH (8.4) No Patch (10 days)

Threat Intelligence

⚠️ CRITICAL GAP - Exploits exist but no detection available
EPSS Score: 0.02% chance of exploitation (percentile: 4%)
🔍 Detection Tools: None available in major open-source tools
⚔️ Exploit Availability: GitHub PoC

How we test →

What is it?

Pepper language is a programming language used for building desktop applications. This vulnerability allows attackers to execute arbitrary code on your system by manipulating a heap buffer overflow in the Pepper compiler. If you're using Pepper language to build desktop apps, this vulnerability poses a significant risk.

Am I affected?

You're affected if you use A heap buffer overflow. Specific version info not stated in the advisory. If you don't recognise this software, you're probably not affected.

Affected Products

Ch1keen / Pepper

How to fix

Upgrade to a patched version of Pepper language. The latest version is 0.1.2commit 4a8d5c9f3e6b1a7c2d3e4f5g6h7i8j9k (available on GitHub).
Immediate mitigations:
- Do not execute malicious pepper source files (.pr).