In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and...
High severity
Unreviewed
Published
Aug 18, 2025
to the GitHub Advisory Database
•
Updated Aug 18, 2025
Description
Published by the National Vulnerability Database
Aug 18, 2025
Published to the GitHub Advisory Database
Aug 18, 2025
Last updated
Aug 18, 2025
In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions prior to 12.6.1204.204, the affected applications lack proper validation of user-supplied data when parsing CO files. This could lead to an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process.
References