Description
An Out-of-Bounds Read vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and prior that could allow an attacker to disclose information or execute arbitrary code when a specially crafted VC6 file is being parsed.
Published: 2026-05-12
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An out‑of‑bounds read vulnerability exists in Ashlar‑Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share builds 12.6.1204.216 and earlier. When a specially crafted VC6 file is parsed, the software reads beyond the intended memory bounds, which can expose sensitive information or enable an attacker to execute arbitrary code. The weakness corresponds to CWE‑125.

Affected Systems

Affected products are Ashlar‑Vellum Argon, Cobalt, Cobalt Share, Lithium, and Xenon. All releases up to and including build 12.6.1204.216 are vulnerable; the vulnerability was fixed in build 12.6.1204.217 and later.

Risk and Exploitability

The CVSS score of 8.4 indicates a high‑severity flaw. No EPSS information is available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves an attacker supplying a malicious VC6 file that is processed by the affected application, potentially allowing local or, if file processing occurs under elevated privileges, remote code execution. Successful exploitation requires the file to be parsed by the vulnerable software, which could be achieved through normal operating procedures that accept user‑supplied files.

Generated by OpenCVE AI on May 12, 2026 at 22:41 UTC.

Remediation

Vendor Solution

Ashlar-Vellum recommends users update to build 12.6.1204.217 and later.


OpenCVE Recommended Actions

  • Upgrade Ashlar‑Vellum to build 12.6.1204.217 or later on all affected products, including Argon, Cobalt, Cobalt Share, Lithium, and Xenon.
  • Restrict or sandbox processing of untrusted VC6 files until the update is applied to prevent accidental exploitation.
  • Monitor application logs for anomalies related to VC6 file parsing that could indicate an attempt to exploit the out‑of‑bounds read.

Generated by OpenCVE AI on May 12, 2026 at 22:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 14 May 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Ashlar
Ashlar argon
Ashlar cobalt
Ashlar cobalt Share
Ashlar lithium
Ashlar xenon
CPEs cpe:2.3:a:ashlar:argon:*:*:*:*:*:*:*:*
cpe:2.3:a:ashlar:cobalt:*:*:*:*:*:*:*:*
cpe:2.3:a:ashlar:cobalt_share:*:*:*:*:*:*:*:*
cpe:2.3:a:ashlar:lithium:*:*:*:*:*:*:*:*
cpe:2.3:a:ashlar:xenon:*:*:*:*:*:*:*:*
Vendors & Products Ashlar
Ashlar argon
Ashlar cobalt
Ashlar cobalt Share
Ashlar lithium
Ashlar xenon
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Wed, 13 May 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Ashlar Vellum
Ashlar Vellum argon
Ashlar Vellum cobalt
Ashlar Vellum cobalt Share
Ashlar Vellum lithium
Ashlar Vellum xenon
Vendors & Products Ashlar Vellum
Ashlar Vellum argon
Ashlar Vellum cobalt
Ashlar Vellum cobalt Share
Ashlar Vellum lithium
Ashlar Vellum xenon

Tue, 12 May 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 12 May 2026 21:00:00 +0000

Type Values Removed Values Added
Description An Out-of-Bounds Read vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and prior that could allow an attacker to disclose information or execute arbitrary code when a specially crafted VC6 file is being parsed.
Title Out-of-bounds read in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, Cobalt Share
Weaknesses CWE-125
References
Metrics cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Ashlar Argon Cobalt Cobalt Share Lithium Xenon
Ashlar Vellum Argon Cobalt Cobalt Share Lithium Xenon
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-05-12T21:12:34.923Z

Reserved: 2025-11-17T16:43:44.054Z

Link: CVE-2025-65087

cve-icon Vulnrichment

Updated: 2026-05-12T21:12:30.414Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-12T21:16:13.570

Modified: 2026-05-14T14:57:34.480

Link: CVE-2025-65087

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-13T10:35:48Z

Weaknesses