CVE-2025-65087
high
CVSS v3
7.8
CVSS v4 NEW
8.4
VIR risk
7.8
Description
An Out-of-Bounds Read vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and prior that could allow an attacker to disclose information or execute arbitrary code when a specially crafted VC6 file is being parsed.
Predictions
Exploit likelihood
75%
Patch ETA
โ
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| ashlar | argon | {"endIncluding":"12.6.1204.216"} | |
| ashlar | cobalt | {"endIncluding":"12.6.1204.216"} | |
| ashlar | cobalt_share | {"endIncluding":"12.6.1204.216"} | |
| ashlar | lithium | {"endIncluding":"12.6.1204.216"} | |
| ashlar | xenon | {"endIncluding":"12.6.1204.216"} | |
References
CWEs
CWE-125
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.