ZDI-26-587: Ashlar-Vellum Cobalt VS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-19781.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ashlar-Vellum Cobaltto a version that resolves this vulnerability.Patch ZDI-26-587 - Compensating control
Because exploitation requires user interaction (victim must visit a malicious page or open a malicious file), mitigate exposure by blocking delivery paths for malicious pages/files (e.g., use web filtering and email/file attachment controls) to prevent users from opening or accessing attacker-controlled content.