Search Results (1 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-52011 1 Vitejs 2 Launch-editor, Vite 2026-06-02 8.3 High
launch-editor allows users to open files with line numbers in editor from Node.js. Prior to version 2.9.0, due to the insufficient sanitization of the `file` argument in the `launchEditor`, an attacker can execute arbitrary commands on Windows by supplying a filename that contains special characters. This issue has been fixed in the `launch-editor` version 2.9.0, corresponding to vite version 5.4.9.