CVE-2024-25255
CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th
Sublime Text 4 was discovered to contain a command injection vulnerability via the New Build System module. NOTE: multiple third parties report that this is intended behavior.
| Vendor | n/a |
| Product | n/a |
| Published | Nov 11, 2024 |
| Last Updated | Dec 24, 2024 |
Stay Ahead of the Next One
Get instant alerts for n/a n/a
Be the first to know when new critical vulnerabilities affecting n/a n/a are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
n/a / n/a
n/a
References
exploitart.ist: https://exploitart.ist/exploit/2023/09/17/sublime-text-os-command-injection.html forum.sublimetext.com: https://forum.sublimetext.com/t/cve-2024-25255-critical/74906/3 sublimetext.com: https://www.sublimetext.com/docs/build_systems.html#exec-target-options sublimetext.com: https://www.sublimetext.com/docs/build_systems.html#shell_cmd.