PatchSiren

Graphite project CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Graphite project CVE published 2026-06-05

CVE-2026-50593

CVE-2026-50593 is a HIGH severity vulnerability in Graphite, a graphics rendering library. The vulnerability is caused by an integer underflow and resultant out-of-bounds write via Graphite actions, specifically in the `slotat` function, which does not ensure that an offset is within the allowed slot-map range. This vulnerability has a CVSS score of 7.3 and can potentially lead to local privilege escalation.