CVE 4.8 MEDIUM

aardappel lobster wfc.h WaveFunctionCollapse memory corruption_CVE-2026-2258

4.8 / 10
MEDIUM
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P

Description

A flaw has been found in aardappel lobster up to 2025.4. Affected by this vulnerability is the function WaveFunctionCollapse in the library dev/src/lobster/wfc.h. Executing a manipulation can lead to memory corruption. The attack can only be executed locally. The exploit has been published and may be used. This patch is called c2047a33e1ac2c42ab7e8704b33f7ea518a11ffd. It is advisable to implement a patch to correct this issue.

Basic Information

ID CVE-2026-2258
Source VulDB
Published Feb 10, 2026 at 00:02

Affected Product

Vendor aardappel
Product lobster
Version 2025.0
Affected Versions aardappel lobster 2025.0
aardappel lobster 2025.1
aardappel lobster 2025.2
aardappel lobster 2025.3
aardappel lobster 2025.4

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.