PT-2026-45495 · Npm · Vite+1
CVE-2024-52011
·
Published
2026-06-01
·
Updated
2026-08-31
CVSS v3.1
8.3
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
launch-editor versions prior to 2.9.0
vite versions prior to 5.4.9
Description
Insufficient sanitization of the
file argument in the launchEditor() function allows an attacker to execute arbitrary commands on Windows systems by providing a filename containing special characters. This can occur if an attacker can place a file with a malicious filename and control the file argument passed to the launchEditor() method, such as through a development server where a malicious website forces the download of a file with a predictable path.Recommendations
Update launch-editor to version 2.9.0 or later.
Update vite to version 5.4.9 or later.
Exploit
Fix
Argument Injection
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Launch-Editor
Vite