Skip to main content

CVE-2025-5917

CVE Details

Visit the official vulnerability details page for CVE-2025-5917 to learn more.

Initial Publication

06/09/2025

Last Update

08/15/2025

Third Party Dependency

libarchive

NIST CVE Summary

A vulnerability has been identified in the libarchive library. This flaw involves an 'off-by-one' miscalculation when handling prefixes and suffixes for file names. This can lead to a 1-byte write overflow. While seemingly small, such an overflow can corrupt adjacent memory, leading to unpredictable program behavior, crashes, or in specific circumstances, could be leveraged as a building block for more sophisticated exploitation.

CVE Severity

5

Our Official Summary

Investigation is ongoing to determine how this vulnerability affects our products.

Status

Analyzed

Affected Products & Versions

VersionPaletteAIPaletteAI VerteX
0.7.1⚠️ Impacted⚠️ Impacted
0.6.6⚠️ Impacted⚠️ Impacted
0.5.11⚠️ Impacted⚠️ Impacted

Revision History

No revisions available.