Type Confusion in Ashlar-Vellum Cobalt VS File Parsing
CVE-2025-2018
7.8HIGH
What is CVE-2025-2018?
A type confusion vulnerability exists in the file parsing mechanism of Ashlar-Vellum Cobalt for VS files. This flaw allows remote attackers to execute arbitrary code by convincing a user to visit a malicious webpage or open a compromised file. The vulnerability arises due to insufficient validation of user-supplied data, leading to unintended consequences in code execution within the context of the current process. To mitigate risk, users should exercise caution when handling VS files and ensure they are sourced from trusted locations.
Affected Version(s)
Cobalt 1204.91