Remote Code Execution Vulnerability in Ashlar-Vellum Graphite Product
CVE-2025-7988
7.8HIGH
What is CVE-2025-7988?
A vulnerability in Ashlar-Vellum Graphite exists due to inadequate validation of user-supplied data during the parsing of VC6 files. This flaw can lead to an out-of-bounds write condition, allowing remote attackers to execute arbitrary code on affected systems. Exploitation requires the user to interact with a malicious file or webpage, thus underlining the need for vigilance in handling VC6 files.
Affected Version(s)
Graphite 13.0