Логотип exploitDog
bind:CVE-2025-12121
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-12121

Количество 3

Количество 3

nvd логотип

CVE-2025-12121

3 месяца назад

Lite XL versions 2.1.8 and prior contain a vulnerability in the system.exec function, which allowed arbitrary command execution through unsanitized shell command construction. This function was used in project directory launching (core.lua), drag-and-drop file handling (rootview.lua), and the “open in system” command in the treeview plugin (treeview.lua). If an attacker could influence input to system.exec, they might execute arbitrary commands with the privileges of the Lite XL process.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-w994-qmmq-w97w

3 месяца назад

Lite XL versions 2.1.8 and prior contain a vulnerability in the system.exec function, which allowed arbitrary command execution through unsanitized shell command construction. This function was used in project directory launching (core.lua), drag-and-drop file handling (rootview.lua), and the “open in system” command in the treeview plugin (treeview.lua). If an attacker could influence input to system.exec, they might execute arbitrary commands with the privileges of the Lite XL process.

CVSS3: 7.3
EPSS: Низкий
fstec логотип

BDU:2026-00072

3 месяца назад

Уязвимость функции system.exec текстового редактора Lite XL Text Editor, позволяющая нарушителю выполнить произвольные команды

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-12121

Lite XL versions 2.1.8 and prior contain a vulnerability in the system.exec function, which allowed arbitrary command execution through unsanitized shell command construction. This function was used in project directory launching (core.lua), drag-and-drop file handling (rootview.lua), and the “open in system” command in the treeview plugin (treeview.lua). If an attacker could influence input to system.exec, they might execute arbitrary commands with the privileges of the Lite XL process.

CVSS3: 7.3
0%
Низкий
3 месяца назад
github логотип
GHSA-w994-qmmq-w97w

Lite XL versions 2.1.8 and prior contain a vulnerability in the system.exec function, which allowed arbitrary command execution through unsanitized shell command construction. This function was used in project directory launching (core.lua), drag-and-drop file handling (rootview.lua), and the “open in system” command in the treeview plugin (treeview.lua). If an attacker could influence input to system.exec, they might execute arbitrary commands with the privileges of the Lite XL process.

CVSS3: 7.3
0%
Низкий
3 месяца назад
fstec логотип
BDU:2026-00072

Уязвимость функции system.exec текстового редактора Lite XL Text Editor, позволяющая нарушителю выполнить произвольные команды

CVSS3: 8.8
0%
Низкий
3 месяца назад

Уязвимостей на страницу