Out-of-Bounds Read Vulnerability in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share
CVE-2025-65087

8.4HIGH

Key Information:

Vendor
CVE Published:
12 May 2026

What is CVE-2025-65087?

An Out-of-Bounds Read vulnerability has been identified in Ashlar-Vellum's suite of products including Cobalt, Xenon, Argon, Lithium, and Cobalt Share. This flaw allows an attacker to exploit the parsing of specially crafted VC6 files, potentially leading to unauthorized information disclosure or execution of arbitrary code. Affected versions include 12.6.1204.216 and earlier. Organizations using these products are strongly advised to implement the latest security updates to mitigate associated risks.

Affected Version(s)

Argon 0 <= 12.6.1204.216

Cobalt 0 <= 12.6.1204.216

Cobalt Share 0 <= 12.6.1204.216

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michael Heinzl reported these vulnerabilities to CISA.
.