CVE-2025-7978 is a remote code execution vulnerability affecting Ashlar-Vellum Graphite, specifically within its VC6 file parsing functionality. The flaw stems from an uninitialized memory variable, allowing attackers to execute arbitrary code in the context of the current process if a user opens a malicious VC6 file or visits a malicious page. With a CVSS score of 7.8 (High), this vulnerability requires user interaction and has high impacts on confidentiality, integrity, and availability. Currently, there is no known active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
13.0.48CPE matchmatch criteria | cpe:2.3:a:ashlar:graphite:13.0.48:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.