Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-53632

Опубликовано: 22 июн. 2026
Источник: redhat
CVSS3: 5.3

Описание

launch-editor allows users to open files with line numbers in editor from Node.js. Prior to 2.14.1, the launch-editor NPM package accesses arbitrary paths including Windows UNC paths. When a UNC path is opened, Windows automatically attempts NTLM authentication to the remote host, causing the user’s NTLMv2 password hash to be leaked to an attacker-controlled SMB server. This can result in credential compromise through offline hash cracking. This vulnerability is fixed in 2.14.1.

A flaw was found in launch-editor. This component, used in Node.js to open files, can be tricked into accessing arbitrary paths, including Windows Universal Naming Convention (UNC) paths. When a malicious UNC path is opened, Windows automatically attempts NTLM authentication to a remote server controlled by an attacker. This action leaks the user's NTLMv2 password hash, which can then be used by an attacker to compromise user credentials through offline cracking.

Отчет

Red Hat rates this issue as having Moderate impact for Red Hat OpenShift AI MLflow images on Windows client scenarios. Linux-based Red Hat Enterprise Linux AI bootc images are not affected because launch-editor UNC-path behavior is Windows-specific.

Меры по смягчению последствий

Avoid using launch-editor on Windows clients against untrusted URLs. Upgrade when updated packages are available.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 4cryostat-openshift-console-plugin-npmNot affected
Cryostat 4launch-editorNot affected
Migration Toolkit for Containersrhmtc/openshift-migration-ui-rhel8Not affected
Node HealthCheck Operatorworkload-availability/node-healthcheck-must-gather-rhel9Not affected
Node HealthCheck Operatorworkload-availability/node-healthcheck-operator-bundleNot affected
Node HealthCheck Operatorworkload-availability/node-healthcheck-rhel9-operatorNot affected
OpenShift Lightspeedopenshift-lightspeed/lightspeed-console-plugin-419-rhel9Not affected
OpenShift Lightspeedopenshift-lightspeed/lightspeed-console-plugin-pf5-rhel9Not affected
OpenShift Lightspeedopenshift-lightspeed/lightspeed-console-plugin-rhel9Not affected
OpenShift Pipelinesopenshift-pipelines/pipelines-console-plugin-pf5-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-73
https://bugzilla.redhat.com/show_bug.cgi?id=2491437launch-editor: launch-editor: Credential compromise via NTLMv2 password hash leak through UNC path access

5.3 Medium

CVSS3

Связанные уязвимости

nvd
около 1 месяца назад

launch-editor allows users to open files with line numbers in editor from Node.js. Prior to 2.14.1, the launch-editor NPM package accesses arbitrary paths including Windows UNC paths. When a UNC path is opened, Windows automatically attempts NTLM authentication to the remote host, causing the user’s NTLMv2 password hash to be leaked to an attacker-controlled SMB server. This can result in credential compromise through offline hash cracking. This vulnerability is fixed in 2.14.1.

github
около 2 месяцев назад

launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows

suse-cvrf
8 дней назад

Security update for agama-web-ui

5.3 Medium

CVSS3