launch-editor vulnerable to command injection via the crafted request on Windows
Published Jun 1, 2026
7.5
HIGHCVSS 4.0
EPSS 0.51%
Description
launch-editor allows users to open files with line numbers in editor from Node.js. Prior to version 2.9.0, due to the insufficient sanitization of the `file` argument in the `launchEditor`, an attacker can execute arbitrary commands on Windows by supplying a filename that contains special characters. This issue has been fixed in the `launch-editor` version 2.9.0, corresponding to vite version 5.4.9.
Affected products
-
- Version < 2.9.0StatusaffectedConstraints-
- Version
-
- Version < 5.4.9StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Vitejs | Launch-Editor | n/a |
| ||||||
| Vitejs | Vite | n/a |
|
No data.
No data.
Cluster Observability Operator 1.5.0
cluster-observability-operator/logging-console-plugin-pf4-rhel9:1782839279
Fixed · RHSA-2026:34342
Cluster Observability Operator 1.5.0
cluster-observability-operator/logging-console-plugin-pf5-rhel9:1782840539
Fixed · RHSA-2026:34342
Cryostat 4
cryostat-openshift-console-plugin-npm
Not affected
Cryostat 4
launch-editor
Not affected
Migration Toolkit for Containers
rhmtc/openshift-migration-ui-rhel8
Not affected
Node HealthCheck Operator
workload-availability/node-healthcheck-must-gather-rhel9
Not affected
Node HealthCheck Operator
workload-availability/node-healthcheck-operator-bundle
Not affected
Node HealthCheck Operator
workload-availability/node-healthcheck-rhel9-operator
Not affected
OpenShift Lightspeed
openshift-lightspeed/lightspeed-console-plugin-419-rhel9
Not affected
OpenShift Lightspeed
openshift-lightspeed/lightspeed-console-plugin-pf5-rhel9
Not affected
OpenShift Lightspeed
openshift-lightspeed/lightspeed-console-plugin-rhel9
Not affected
OpenShift Pipelines
openshift-pipelines/pipelines-console-plugin-pf5-rhel9
Not affected
OpenShift Pipelines
openshift-pipelines/pipelines-console-plugin-rhel8
Not affected
OpenShift Pipelines
openshift-pipelines/pipelines-console-plugin-rhel9
Not affected
OpenShift Pipelines
openshift-pipelines/pipelines-hub-ui-rhel8
Not affected
OpenShift Pipelines
openshift-pipelines/pipelines-hub-ui-rhel9
Not affected
OpenShift Service Mesh 2
openshift-service-mesh/kiali-ossmc-rhel8
Not affected
OpenShift Service Mesh 2
openshift-service-mesh/kiali-rhel8
Not affected
OpenShift Service Mesh 3
openshift-service-mesh/kiali-operator-bundle
Not affected
OpenShift Service Mesh 3
openshift-service-mesh/kiali-ossmc-rhel9
Not affected
OpenShift Service Mesh 3
openshift-service-mesh/kiali-rhel9
Not affected
OpenShift Service Mesh 3
openshift-service-mesh/kiali-rhel9-operator
Not affected
Red Hat AMQ Broker 7
launch-editor
Not affected
Red Hat AMQ Broker 7
vite
Not affected
Red Hat Ansible Automation Platform 2
ansible-automation-platform-24/lightspeed-rhel8
Not affected
Red Hat Ansible Automation Platform 2
ansible-automation-platform-25/lightspeed-rhel8
Not affected
Red Hat Ansible Automation Platform 2
ansible-automation-platform-26/gateway-rhel9
Not affected
Red Hat Ansible Automation Platform 2
ansible-automation-platform-26/lightspeed-rhel9
Not affected
Red Hat Ansible Automation Platform 2
ansible-automation-platform-27/gateway-rhel9
Not affected
Red Hat Ansible Automation Platform 2
ansible-automation-platform-27/lightspeed-rhel9
Not affected
Red Hat Ansible Automation Platform 2
automation-controller
Not affected
Red Hat Ansible Automation Platform 2
automation-eda-controller
Not affected
Red Hat Ansible Automation Platform 2
automation-gateway
Not affected
Red Hat Ansible Automation Platform 2
automation-platform-ui
Not affected
Red Hat Build of Keycloak
vite
Not affected
Red Hat Build of Podman Desktop
rh-podman-desktop.git
Not affected
Red Hat Build of Podman Desktop - Tech Preview
rhdesktop/rh-podman-desktop-ext-bootc-rhel10
Not affected
Red Hat Build of Podman Desktop - Tech Preview
rhdesktop/rh-podman-desktop-ext-openshift-local-rhel10
Not affected
Red Hat Build of Podman Desktop - Tech Preview
rhdesktop/rh-podman-desktop-ext-redhat-account-rhel10
Not affected
Red Hat Build of Podman Desktop - Tech Preview
rhdesktop/rh-podman-desktop-ext-rhel-rhel10
Not affected
Red Hat Build of Podman Desktop - Tech Preview
rhdesktop/rh-podman-desktop-ext-sandbox-rhel10
Not affected
Red Hat Data Grid 8
launch-editor
Not affected
Red Hat Developer Hub
rhdh/rhdh-hub-rhel9
Not affected
Red Hat Discovery 2
discovery/discovery-ui-rhel9
Not affected
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-cuda-rhel9
Not affected
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-gaudi-rhel9
Not affected
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-rocm-rhel9
Not affected
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/disk-image-cuda-rhel9
Not affected
Red Hat JBoss Enterprise Application Platform 8
vite
Not affected
Red Hat JBoss Enterprise Application Platform Expansion Pack
vite
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-mlflow-rhel9
Not affected
Red Hat OpenShift Container Platform 4
openshift4/ose-agent-installer-ui-rhel9
Not affected
Red Hat OpenShift Container Platform 4
openshift4/ose-console-rhel9
Not affected
Red Hat OpenShift Dev Spaces
devspaces/openvsx-rhel9
Not affected
Red Hat OpenShift Virtualization 4
container-native-virtualization/kubevirt-console-plugin-rhel9
Not affected
Red Hat Quay 3
quay/quay-rhel8
Not affected
Red Hat build of Apache Camel - HawtIO 4
launch-editor
Not affected
Self-service automation portal 2
ansible-automation-platform/automation-portal
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Cluster Observability Operator 1.5.0 | cluster-observability-operator/logging-console-plugin-pf4-rhel9:1782839279 | Fixed | RHSA-2026:34342 |
| Cluster Observability Operator 1.5.0 | cluster-observability-operator/logging-console-plugin-pf5-rhel9:1782840539 | Fixed | RHSA-2026:34342 |
| Cryostat 4 | cryostat-openshift-console-plugin-npm | Not affected | n/a |
| Cryostat 4 | launch-editor | Not affected | n/a |
| Migration Toolkit for Containers | rhmtc/openshift-migration-ui-rhel8 | Not affected | n/a |
| Node HealthCheck Operator | workload-availability/node-healthcheck-must-gather-rhel9 | Not affected | n/a |
| Node HealthCheck Operator | workload-availability/node-healthcheck-operator-bundle | Not affected | n/a |
| Node HealthCheck Operator | workload-availability/node-healthcheck-rhel9-operator | Not affected | n/a |
| OpenShift Lightspeed | openshift-lightspeed/lightspeed-console-plugin-419-rhel9 | Not affected | n/a |
| OpenShift Lightspeed | openshift-lightspeed/lightspeed-console-plugin-pf5-rhel9 | Not affected | n/a |
| OpenShift Lightspeed | openshift-lightspeed/lightspeed-console-plugin-rhel9 | Not affected | n/a |
| OpenShift Pipelines | openshift-pipelines/pipelines-console-plugin-pf5-rhel9 | Not affected | n/a |
| OpenShift Pipelines | openshift-pipelines/pipelines-console-plugin-rhel8 | Not affected | n/a |
| OpenShift Pipelines | openshift-pipelines/pipelines-console-plugin-rhel9 | Not affected | n/a |
| OpenShift Pipelines | openshift-pipelines/pipelines-hub-ui-rhel8 | Not affected | n/a |
| OpenShift Pipelines | openshift-pipelines/pipelines-hub-ui-rhel9 | Not affected | n/a |
| OpenShift Service Mesh 2 | openshift-service-mesh/kiali-ossmc-rhel8 | Not affected | n/a |
| OpenShift Service Mesh 2 | openshift-service-mesh/kiali-rhel8 | Not affected | n/a |
| OpenShift Service Mesh 3 | openshift-service-mesh/kiali-operator-bundle | Not affected | n/a |
| OpenShift Service Mesh 3 | openshift-service-mesh/kiali-ossmc-rhel9 | Not affected | n/a |
| OpenShift Service Mesh 3 | openshift-service-mesh/kiali-rhel9 | Not affected | n/a |
| OpenShift Service Mesh 3 | openshift-service-mesh/kiali-rhel9-operator | Not affected | n/a |
| Red Hat AMQ Broker 7 | launch-editor | Not affected | n/a |
| Red Hat AMQ Broker 7 | vite | Not affected | n/a |
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-24/lightspeed-rhel8 | Not affected | n/a |
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-25/lightspeed-rhel8 | Not affected | n/a |
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-26/gateway-rhel9 | Not affected | n/a |
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-26/lightspeed-rhel9 | Not affected | n/a |
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-27/gateway-rhel9 | Not affected | n/a |
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-27/lightspeed-rhel9 | Not affected | n/a |
| Red Hat Ansible Automation Platform 2 | automation-controller | Not affected | n/a |
| Red Hat Ansible Automation Platform 2 | automation-eda-controller | Not affected | n/a |
| Red Hat Ansible Automation Platform 2 | automation-gateway | Not affected | n/a |
| Red Hat Ansible Automation Platform 2 | automation-platform-ui | Not affected | n/a |
| Red Hat Build of Keycloak | vite | Not affected | n/a |
| Red Hat Build of Podman Desktop | rh-podman-desktop.git | Not affected | n/a |
| Red Hat Build of Podman Desktop - Tech Preview | rhdesktop/rh-podman-desktop-ext-bootc-rhel10 | Not affected | n/a |
| Red Hat Build of Podman Desktop - Tech Preview | rhdesktop/rh-podman-desktop-ext-openshift-local-rhel10 | Not affected | n/a |
| Red Hat Build of Podman Desktop - Tech Preview | rhdesktop/rh-podman-desktop-ext-redhat-account-rhel10 | Not affected | n/a |
| Red Hat Build of Podman Desktop - Tech Preview | rhdesktop/rh-podman-desktop-ext-rhel-rhel10 | Not affected | n/a |
| Red Hat Build of Podman Desktop - Tech Preview | rhdesktop/rh-podman-desktop-ext-sandbox-rhel10 | Not affected | n/a |
| Red Hat Data Grid 8 | launch-editor | Not affected | n/a |
| Red Hat Developer Hub | rhdh/rhdh-hub-rhel9 | Not affected | n/a |
| Red Hat Discovery 2 | discovery/discovery-ui-rhel9 | Not affected | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-cuda-rhel9 | Not affected | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-gaudi-rhel9 | Not affected | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-rocm-rhel9 | Not affected | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/disk-image-cuda-rhel9 | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 8 | vite | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | vite | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-mlflow-rhel9 | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-agent-installer-ui-rhel9 | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-console-rhel9 | Not affected | n/a |
| Red Hat OpenShift Dev Spaces | devspaces/openvsx-rhel9 | Not affected | n/a |
| Red Hat OpenShift Virtualization 4 | container-native-virtualization/kubevirt-console-plugin-rhel9 | Not affected | n/a |
| Red Hat Quay 3 | quay/quay-rhel8 | Not affected | n/a |
| Red Hat build of Apache Camel - HawtIO 4 | launch-editor | Not affected | n/a |
| Self-service automation portal 2 | ansible-automation-platform/automation-portal | Not affected | n/a |
launch-editor
npm
Introduced 0 Fixed 2.9.0vite
npm
Introduced 0 Fixed 5.4.9
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | launch-editor | 0 | 2.9.0 |
| npm | vite | 0 | 5.4.9 |
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Metrics
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
1 other source (NVD) ▾
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
TotalDecision
n/aAssessed Jun 2, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Jun–Oct 2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.51% (0.00514) | 41.64th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.42% (0.00424) | 33.69th | v5 (v2026.06.15) |
| Jun 2, 2026 | 0.06% (0.00060) | 18.89th | v4 (v2025.03.14) |
References (10)
- https://access.redhat.com/errata/RHSA-2026:34342
- https://access.redhat.com/security/cve/CVE-2024-52011 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2483853 Issue Tracking
- https://github.com/advisories/GHSA-c27g-q93r-2cwf Advisory
- https://github.com/vitejs/launch-editor/commit/971291e8a6a91226e1616c5c0ec85423d2d50a5e x_refsource_MISC
- https://github.com/vitejs/launch-editor/security/advisories/GHSA-c27g-q93r-2cwf x_refsource_CONFIRM
- https://github.com/yyx990803/launch-editor/security/advisories/GHSA-c27g-q93r-2cwf
- https://nvd.nist.gov/vuln/detail/CVE-2024-52011
- https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-52011.json
- https://www.cve.org/CVERecord?id=CVE-2024-52011
Change history (0)
No recorded changes yet.