CVE-2025-57107

HIGH

Vtk < 9.5.0 - Heap Buffer Overflow

Title source: rule
STIX 2.1

Description

Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap buffer overflow vulnerability in vtkGLTFDocumentLoader. When processing specially crafted GLTF files, the copy constructor of Accessor objects fails to properly validate buffer boundaries before performing memory read operations.

References (1)

Core 1
Core References
Exploit, Issue Tracking, Third Party Advisory
https://gitlab.kitware.com/vtk/vtk/-/issues/19732

Scores

CVSS v3 7.1
EPSS 0.0002
EPSS Percentile 5.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-122
Status published
Products (1)
vtk/vtk < 9.5.0
Published Oct 31, 2025
Tracked Since Feb 18, 2026