The argon2i_32 implementation does not check the nb_blocks size. If the caller does not provide a sufficiently large buffer based on the API contract, then argon2i_32 will write past the end of the buffer and possibly corrupt the heap.
Fixed in 4.0.2.8, which now verifies that nb_blocks is large enough. See 90ff5b1.
Provide a correctly sized nb_blocks buffer.
pymonocypher thanks Haris (hextheshadow) for the vulnerability report, details, and recommended fix.
4.0.2.8Exploitability
AV:LAC:LAT:NPR:NUI:NVulnerable System
VC:NVI:LVA:LSubsequent System
SC:NSI:NSA:N5.1/CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N