๐Ÿ” CVE Alert

CVE-2026-42881

UNKNOWN 0.0

STIGQter: Arbitrary File Write leading to Local Code Execution via Export HTML

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

STIGQter is an open-source reimplementation of DISA's STIG Viewer. From 0.1.2 to before 1.2.7, an attacker can achieve local code execution (LCE) with the privileges of the user running STIGQter. This requires user interaction: the victim must open the malicious .stigqter file and explicitly run the "Export HTML" action. This vulnerability is fixed in 1.2.7.

CWE CWE-22 CWE-73
Vendor squinky86
Product stigqter
Published May 14, 2026
Stay Ahead of the Next One

Get instant alerts for squinky86 stigqter

Be the first to know when new unknown vulnerabilities affecting squinky86 stigqter are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

squinky86 / STIGQter
>= 0.1.2, < 1.2.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/squinky86/STIGQter/security/advisories/GHSA-mcv5-5j7p-vqh7 bitwizemusic.com: https://www.bitwizemusic.com/security/advisories/bve-2026-0007