Lite XL versions 2.1.8 and prior automatically execute the .lite_project.lua file when opening a project directory, without prompting the user for confirmation. The .lite_project.lua file is intended for project-specific configuration but can contain executable Lua logic. This behavior could allow execution of untrusted Lua code if a user opens a malicious project, potentially leading to arbitrary code execution with the privileges of the Lite XL process.
History

Mon, 24 Nov 2025 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Lite Xl
Lite Xl lite Xl
Vendors & Products Lite Xl
Lite Xl lite Xl

Thu, 20 Nov 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Nov 2025 16:45:00 +0000

Type Values Removed Values Added
Description Lite XL versions 2.1.8 and prior automatically execute the .lite_project.lua file when opening a project directory, without prompting the user for confirmation. The .lite_project.lua file is intended for project-specific configuration but can contain executable Lua logic. This behavior could allow execution of untrusted Lua code if a user opens a malicious project, potentially leading to arbitrary code execution with the privileges of the Lite XL process.
Title CVE-2025-12120
References

cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published: 2025-11-20T16:38:29.108Z

Updated: 2025-11-20T18:09:45.449Z

Reserved: 2025-10-23T18:11:16.473Z

Link: CVE-2025-12120

cve-icon Vulnrichment

Updated: 2025-11-20T18:09:32.727Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-11-20T17:15:48.640

Modified: 2025-11-21T15:13:13.800

Link: CVE-2025-12120

cve-icon Redhat

No data.