PT-2026-7197 · Wfc.H+1 · Wfc.H+1

Oneafter

·

Published

2026-02-10

·

Updated

2026-02-17

·

CVE-2026-2258

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions aardappel lobster versions prior to 2025.4
Description A flaw exists in the WaveFunctionCollapse function within the dev/src/lobster/wfc.h library. A manipulation of this function can lead to memory corruption. The attack is limited to local execution. An exploit for this issue has been published.
Recommendations Implement the patch c2047a33e1ac2c42ab7e8704b33f7ea518a11ffd to correct this issue.

Exploit

Fix

Buffer Overflow

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2026-2258

Affected Products

Aardappel Lobster
Wfc.H