{"id":"CVE-2025-8854","summary":"bullet3 VHACD utility: stack-based buffer overflow in OFF parser (LoadOFF)","details":"Stack-based buffer overflow in LoadOFF in bulletphysics bullet3 before 3.26 on all platforms allows remote attackers to execute arbitrary code via a crafted OFF file with an overlong initial token processed by the VHACD test utility or invoked indirectly through PyBullet's vhacd function.","modified":"2026-08-12T03:51:12.550886647Z","published":"2025-08-11T04:24:02.469Z","database_specific":{"cwe_ids":["CWE-120"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/8xxx/CVE-2025-8854.json","cna_assigner":"CyberArk"},"references":[{"type":"WEB","url":"https://github.com/bulletphysics/bullet3/blob/master/Extras/VHACD/test/src/main_vhacd.cpp#L472"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/8xxx/CVE-2025-8854.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-8854"},{"type":"REPORT","url":"https://github.com/bulletphysics/bullet3/issues/4732"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/bulletphysics/bullet3","events":[{"introduced":"0"},{"last_affected":"2c204c49e56ed15ec5fcfa71d199ab6d6570b3f5"}],"database_specific":{"source":["AFFECTED_FIELD","CPE_RANGE"],"cpe":"cpe:2.3:a:bulletphysics:pybullet:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"3.25"}]}}],"versions":["3.25","3.24","3.23","3.22b","3.22a","3.22","3.21","3.17","3.05","3.09","3.08","3.07","3.06","2.89","2.88","2.87","2.86.1","2.86","2.85.1","2.85","2.84","2.83.7","2.83.6","2.83.5","2.83.4","2.83"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-8854.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}