Behaviortree is a focused behavior-tree execution framework where vulnerabilities center on the core product and exhibit patterns characteristic of C/C++ resource management: improper resource shutdown, NULL pointer dereferences, buffer overflows, and memory-bounds violations. These weaknesses reflect the manual memory handling demands of the library and the risks inherent to state-machine implementations that process untrusted tree definitions.
The number and severity of CVEs published that impact products developed by Behaviortree over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-11012HIGH A vulnerability was determined in BehaviorTree up to 4.7.0. This affects the function ParseScript of the file /src/script_parser.cpp of the component Diagnostic Message Handler. Ex | Sep 26, 2025 | 7.8 | 25 | NO | NO |
CVE-2025-11011MEDIUM A vulnerability was found in BehaviorTree up to 4.7.0. Affected by this issue is the function JsonExporter::fromJson of the file /src/json_export.cpp. Performing manipulation of th | Sep 26, 2025 | 5.5 | 22 | NO | NO |
CVE-2025-11013MEDIUM A vulnerability was identified in BehaviorTree up to 4.7.0. This vulnerability affects the function XMLParser::PImpl::loadDocImpl of the file /src/xml_parsing.cpp of the component | Sep 26, 2025 | 5.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Behaviortree.
Media articles that mention a CVE ID that affects a product developed by Behaviortree — matched by CVE ID, not by vendor name.