ZDI-CAN-28173: ZDI-26-587: Ashlar-Vellum Cobalt VS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-19781.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch ZDI-26-587 - Compensating control
Since remote code execution requires user interaction, reduce exposure by restricting access to the affected Ashlar-Vellum Cobalt environment (e.g., limit reachable endpoints and block inbound access) and encourage users not to open untrusted files or visit untrusted web pages.