PT-2026-49575 · Npm · Launch-Editor
CVSS v4.0
5.5
Medium
| Vector | AV:N/AC:H/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
launch-editor versions prior to 2.14.1
Description
The launch-editor NPM package allows the access of arbitrary paths, including Windows UNC (Universal Naming Convention) paths. On Windows systems, accessing a UNC path triggers an automatic NTLM (New Technology LAN Manager) authentication attempt to the remote SMB (Server Message Block) server without requiring user interaction. If an attacker controls the remote SMB server, the user's NTLMv2 password hash is leaked, which can then be subjected to offline hash cracking to reveal the cleartext password. This issue can be triggered via the
file parameter in the / open-in-editor endpoint.Recommendations
Update to version 2.14.1.
Disable NTLM to prevent automatic authentication attempts to remote hosts.
Exploit
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Launch-Editor