← Vulnerability feed

Vulnerability record · CVE-2025-53510 · published 25 August 2025

CVE-2025-53510: Sail vulnerability

Sail · Sail

A memory corruption vulnerability exists in the PSD Image Decoding functionality of the SAIL Image Decoding Library v0.9.8. When loading a specially crafted .psd file, an integer overflow can be made to occur when calculating the stride for decoding. Afterwards, this will cause a heap-based buffer to overflow when decoding the image which can lead to remote code execution. An attacker will need to convince the library to read a file to trigger this vulnerability.

8.8 CVSS 3.1 High EPSS 0.69% · top 49.2% CWE-680 · CWE-680
8.8CVSS 3.1 base score
0.69%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

A memory corruption vulnerability exists in the PSD Image Decoding functionality of the SAIL Image Decoding Library v0.9.8. When loading a specially crafted .psd file, an integer overflow can be made to occur when calculating the stride for decoding. Afterwards, this will cause a heap-based buffer to overflow when decoding the image which can lead to remote code execution. An attacker will need to convince the library to read a file to trigger this vulnerability.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-53510 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-27168Sail heap-based buffer overflow vulnerabilitySAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. All versions are vulnerable to…EPSS 0.66%8.8CVE-2025-52456Sail vulnerabilityA memory corruption vulnerability exists in the WebP Image Decoding functionality of the SAIL Image Decoding Library v0.9.8. When loading a specially…EPSS 0.86%8.8CVE-2025-52930Sail vulnerabilityA memory corruption vulnerability exists in the BMPv3 RLE Decoding functionality of the SAIL Image Decoding Library v0.9.8. When decompressing the im…EPSS 0.93%8.8CVE-2025-53085Sail heap-based buffer overflow vulnerabilityA memory corruption vulnerability exists in the PSD RLE Decoding functionality of the SAIL Image Decoding Library v0.9.8. When decompressing the imag…EPSS 0.93%8.8CVE-2025-35984Sail heap-based buffer overflow vulnerabilityA memory corruption vulnerability exists in the PCX Image Decoding functionality of the SAIL Image Decoding Library v0.9.8. When decoding the image d…EPSS 1.4%8.8CVE-2025-46407Sail vulnerabilityA memory corruption vulnerability exists in the BMPv3 Palette Decoding functionality of the SAIL Image Decoding Library v0.9.8. When loading a specia…EPSS 0.66%8.8CVE-2025-50129Sail heap-based buffer overflow vulnerabilityA memory corruption vulnerability exists in the PCX Image Decoding functionality of the SAIL Image Decoding Library v0.9.8. When decoding the image d…EPSS 0.93%8.8CVE-2025-32468Sail vulnerabilityA memory corruption vulnerability exists in the BMPv3 Image Decoding functionality of the SAIL Image Decoding Library v0.9.8. When loading a speciall…EPSS 0.86%

Source: NIST National Vulnerability Database (record CVE-2025-53510), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.