CVE-2025-11011
A vulnerability was found in BehaviorTree up to 4.7.0. Affected by this issue is the function JsonExporter::fromJson of the file /src/json_export.cpp. Performing manipulation of the argument Source results in null pointer dereference. The attack needs to be approached locally. The exploit has been made public and could be used. The patch is named 4b23dcaf0ce951a31299ebdd61df69f9ce99a76d. It is suggested to install a patch to address this issue.
Vendor
Product
CWE
Yayın Tarihi
2025-09-26 12:15:34
Güncelleme
2025-10-16 15:53:52
Source Identifier
cna@vuldb.com
KEV Date Added
-
Kategoriler
Referanslar
https://github.com/BehaviorTree/BehaviorTree.CPP/commit/4b23dcaf0ce951a31299ebdd61df69f9ce99a76d
https://github.com/BehaviorTree/BehaviorTree.CPP/issues/1008
https://github.com/BehaviorTree/BehaviorTree.CPP/pull/1009
https://github.com/user-attachments/files/22270928/poc.zip
https://vuldb.com/?ctiid.325954
https://vuldb.com/?id.325954
https://vuldb.com/?submit.654073