Ashlar maintains a highly specialized portfolio of design and visualization software serving professional engineering and architectural workflows, with a notably concentrated product line including Cobalt, Graphite, Argon, Lithium, and Xenon. Despite this narrow product scope, the vendor's vulnerability footprint is well-represented in the landscape, reflecting the complexity inherent to graphics-intensive and geometry-processing applications. The recurring vulnerability pattern centers on memory-safety issues—out-of-bounds reads and writes, heap and stack buffer overflows, and type-confusion flaws—that are characteristic of native codebases handling unstructured geometric and design data. These weakness classes pose particular risk in environments where Ashlar tools process untrusted or adversarially crafted design files, as such flaws can lead to memory corruption and code execution within design workflows. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ashlar over time
Signals from CVEs in this vendor scope (104 CVEs).
104 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-2023HIGH Ashlar-Vellum Cobalt LI File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installa | Mar 11, 2025 | 7.8 | 31 | NO | NO |
CVE-2025-2021HIGH Ashlar-Vellum Cobalt XE File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installa | Mar 11, 2025 | 7.8 | 31 | NO | NO |
CVE-2025-65085CRITICAL A Heap-based Buffer Overflow vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and prior that could allow an attacker | Nov 25, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-65088HIGH An Out-of-Bounds Read vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and prior that could allow an attacker to dis | May 12, 2026 | 7.8 | 28 | NO | NO |
CVE-2025-65087HIGH An Out-of-Bounds Read vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and prior that could allow an attacker to dis | May 12, 2026 | 7.8 | 28 | NO | NO |
CVE-2025-65086HIGH An Out-of-Bounds Write vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and prior that could allow an attacker to ex | May 12, 2026 | 7.8 | 28 | NO | NO |
CVE-2025-65084CRITICAL An Out-of-Bounds Write vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and prior that could allow an attacker to di | Nov 25, 2025 | 9.8 | 27 | NO | NO |
CVE-2025-8000HIGH Ashlar-Vellum Cobalt LI File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installati | Sep 17, 2025 | 7.8 | 27 | NO | NO |
CVE-2025-2022HIGH Ashlar-Vellum Cobalt VS File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installati | Mar 11, 2025 | 7.8 | 27 | NO | NO |
CVE-2025-2020HIGH Ashlar-Vellum Cobalt VC6 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected inst | Mar 11, 2025 | 7.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (104 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ashlar.
Media articles that mention a CVE ID that affects a product developed by Ashlar — matched by CVE ID, not by vendor name.