CVE-2026-42881
STIGQter: Arbitrary File Write leading to Local Code Execution via Export HTML
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
STIGQter is an open-source reimplementation of DISA's STIG Viewer. From 0.1.2 to before 1.2.7, an attacker can achieve local code execution (LCE) with the privileges of the user running STIGQter. This requires user interaction: the victim must open the malicious .stigqter file and explicitly run the "Export HTML" action. This vulnerability is fixed in 1.2.7.
| CWE | CWE-22 CWE-73 |
| Vendor | squinky86 |
| Product | stigqter |
| Published | May 14, 2026 |
Stay Ahead of the Next One
Get instant alerts for squinky86 stigqter
Be the first to know when new unknown vulnerabilities affecting squinky86 stigqter are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
squinky86 / STIGQter
>= 0.1.2, < 1.2.7