CVE 7.3 HIGH

CVE-2025-12121_CVE-2025-12121

7.3 / 10
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Description

Lite XL versions 2.1.8 and prior contain a vulnerability in the system.exec function, which allowed arbitrary command execution through unsanitized shell command construction. This function was used in project directory launching (core.lua), drag-and-drop file handling (rootview.lua), and the β€œopen in system” command in the treeview plugin (treeview.lua). If an attacker could influence input to system.exec, they might execute arbitrary commands with the privileges of the Lite XL process.

Basic Information

ID CVE-2025-12121
Source certcc
Published Nov 20, 2025 at 16:39
Modified Nov 20, 2025 at 18:10

Affected Product

Vendor Lite XL
Product Lite XL
Version 2.1.8 and earlier
Affected Versions Lite XL Lite XL 2.1.8 and earlier

References

πŸ’­ Join the Security Discussion

πŸ”’ Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.