CVE-2025-11011

LOW

BehaviorTree <4.7.0 - Null Pointer Dereference

Title source: llm
STIX 2.1

Description

A vulnerability was found in BehaviorTree up to 4.7.0. Affected by this issue is the function JsonExporter::fromJson of the file /src/json_export.cpp. Performing manipulation of the argument Source results in null pointer dereference. The attack needs to be approached locally. The exploit has been made public and could be used. The patch is named 4b23dcaf0ce951a31299ebdd61df69f9ce99a76d. It is suggested to install a patch to address this issue.

References (7)

Core 7
Core References
Third Party Advisory, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.325954
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.325954
Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.654073
Exploit, Issue Tracking, Third Party Advisory issue-tracking
https://github.com/BehaviorTree/BehaviorTree.CPP/issues/1008

Scores

CVSS v3 3.3
EPSS 0.0018
EPSS Percentile 8.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-404 CWE-476
Status published
Products (1)
behaviortree/behaviortree < 4.7.3
Published Sep 26, 2025
Tracked Since Feb 18, 2026