๐Ÿ” CVE Alert

CVE-2026-59561

HIGH 7.8
CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
0th

Sakura Editor provided by Sakura Editor Development Community contains an OS command injection vulnerability. If a victim user is directed to edit a file in a crafted directory, arbitrary OS command may be executed on the user's PC when the user invokes "Open Terminal".

Vendor sakura editor development community
Product sakura editor
Published Aug 24, 2026
Stay Ahead of the Next One

Get instant alerts for sakura editor development community sakura editor

Be the first to know when new high vulnerabilities affecting sakura editor development community sakura editor are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Versions

Sakura Editor Development Community / Sakura Editor
0 < 2.4.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/sakura-editor/sakura/security/advisories/GHSA-6x2x-729r-wjh5 github.com: https://github.com/sakura-editor/sakura/releases/tag/v2.4.3 jvn.jp: https://jvn.jp/en/jp/JVN74538868/