A vulnerability, which was classified as problematic, was found in aardappel lobster up to 2025.4. Affected by this vulnerability is the function WaveFunctionCollapse in the library dev/src/lobster/wfc.h. Executing a manipulation can lead to memory corruption.

The identification of this vulnerability is CVE-2026-2258. The attack can only be executed locally. Furthermore, there is an exploit available.

It is advisable to implement a patch to correct this issue.