Back

HIGH

launch-editor vulnerable to command injection via the crafted request on Windows

Published Jun 1, 2026

Description

launch-editor allows users to open files with line numbers in editor from Node.js. Prior to version 2.9.0, due to the insufficient sanitization of the `file` argument in the `launchEditor`, an attacker can execute arbitrary commands on Windows by supplying a filename that contains special characters. This issue has been fixed in the `launch-editor` version 2.9.0, corresponding to vite version 5.4.9.

Affected products

Remediation

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Metrics

Weaknesses (2)

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Jun 1, 2026
Updated Sep 4, 2026
Reserved Nov 4, 2024
CISA Vulnrichment
Updated Jun 2, 2026
NVD
Status Deferred
Modified Sep 4, 2026
Red Hat
Severity Important
Public date Jun 1, 2026
GHSA-C27G-Q93R-2CWF