A vulnerability was identified in BehaviorTree up to 4.7.0. This vulnerability affects the function XMLParser::PImpl::loadDocImpl of the file /src/xml_parsing.cpp of the component XML Parser. The manipulation leads to null pointer dereference. The attack can only be performed from a local environment. The exploit is publicly available and might be used.
References
Link | Resource |
---|---|
https://github.com/BehaviorTree/BehaviorTree.CPP/issues/1003 | Exploit Issue Tracking |
https://github.com/BehaviorTree/BehaviorTree.CPP/pull/1004 | Issue Tracking |
https://github.com/user-attachments/files/22245915/poc.zip | Exploit |
https://vuldb.com/?ctiid.325956 | Permissions Required VDB Entry |
https://vuldb.com/?id.325956 | Third Party Advisory VDB Entry |
https://vuldb.com/?submit.654075 | Third Party Advisory VDB Entry |
https://github.com/BehaviorTree/BehaviorTree.CPP/issues/1003 | Exploit Issue Tracking |
https://github.com/user-attachments/files/22245915/poc.zip | Exploit |
Configurations
History
16 Oct 2025, 15:53
Type | Values Removed | Values Added |
---|---|---|
First Time |
Behaviortree behaviortree
Behaviortree |
|
CPE | cpe:2.3:a:behaviortree:behaviortree:*:*:*:*:*:*:*:* | |
References | () https://github.com/BehaviorTree/BehaviorTree.CPP/issues/1003 - Exploit, Issue Tracking | |
References | () https://github.com/BehaviorTree/BehaviorTree.CPP/pull/1004 - Issue Tracking | |
References | () https://github.com/user-attachments/files/22245915/poc.zip - Exploit | |
References | () https://vuldb.com/?ctiid.325956 - Permissions Required, VDB Entry | |
References | () https://vuldb.com/?id.325956 - Third Party Advisory, VDB Entry | |
References | () https://vuldb.com/?submit.654075 - Third Party Advisory, VDB Entry |
26 Sep 2025, 13:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-09-26 13:15
Updated : 2025-10-16 15:53
NVD link : CVE-2025-11013
Mitre link : CVE-2025-11013
CVE.ORG link : CVE-2025-11013
JSON object : View
Products Affected
behaviortree
- behaviortree