
Three memory-safety bugs in Godot's untrusted-file parsers
securityvulnerabilitymemory-safetyGodotgame-enginebuffer-overflowfile-parser
Three memory-safety bugs have been discovered in Godot game engine's file parsers, present since versions 1.0 and 3.0, and still existing in current releases. The bugs allow attackers to trigger buffer overreads or overwrites through maliciously crafted data files, potentially affecting exported games that load community-authored content. The post author reports that Godot maintainers do not consider this a security issue, and includes their response along with the author's reply.