← Back to browse · API

CVE-2021-40401

Severity
CRITICAL
CVSS
10.0
EPSS
0.01324
Risk score
40.46
CISA KEV
No
PoC
No
Published
2022-02-04
Modified
2025-04-15
First seen
2026-08-07
Aliases
EUVD-2021-27578, GHSA-X68J-PWCM-V888
Products
Gerbv:Gerbv Gerbv 2.7.0 ,Gerbv forked 2.7.1 ,Gerbv dev (commit b5f1eacd)
Sources
euvd EUVD-2021-27578

Description

A use-after-free vulnerability exists in the RS-274X aperture definition tokenization functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) and Gerbv forked 2.7.1. A specially-crafted gerber file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

References