PT-2025-39634 · Unknown · Behaviortree

Sand

·

Published

2025-09-26

·

Updated

2025-10-16

·

CVE-2025-11013

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions BehaviorTree versions prior to 4.7.1
Description A flaw exists in BehaviorTree due to a null pointer dereference within the XMLParser::PImpl::loadDocImpl function located in the /src/xml parsing.cpp file of the XML Parser component. This issue can be triggered locally. The exploit is publicly available.
Recommendations Update BehaviorTree to version 4.7.1 or later. As a temporary workaround, consider restricting access to the XML Parser component to minimize the risk of exploitation.

Exploit

Fix

Improper Resource Release

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

CVE-2025-11013

Affected Products

Behaviortree