PT-2026-46090 · Npm · Launch-Editor+1
Publicado
2026-06-03
·
Atualizado
2026-06-03
CVSS v4.0
7.5
Alta
| Vetor | AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Summary
Due to the insufficient sanitization of the
file argument in the launchEditor, an attacker can execute arbitrary commands on Windows by supplying a filename that contains special characters.Impact
If the following conditions are met, an attacker can execute arbitrary commands on the computer that is using the
launch-editor:- An attacker can place a file with the malicious filename
- An attacker can call the
launchEditormethod with thefileargument controlled - The
launch-editorpackage is running on Windows
For example, some development server using this package satisfy these conditions, as a malicious website might be able to force the downloading of a file and the path of that file is predictable.
Patch
This issue has been fixed in the
launch-editor version 2.9.0 (commit).Correção
Command Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Launch-Editor
Vite