Lite XL versions 2.1.8 and prior contain a vulnerability in the system.exec function, which allowed arbitrary command execution through unsanitized shell command construction. This function was used in project directory launching (core.lua), drag-and-drop file handling (rootview.lua), and the “open in system” command in the treeview plugin (treeview.lua). If an attacker could influence input to system.exec, they might execute arbitrary commands with the privileges of the Lite XL process.
History

Mon, 24 Nov 2025 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Lite Xl
Lite Xl lite Xl
Vendors & Products Lite Xl
Lite Xl lite Xl

Thu, 20 Nov 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Nov 2025 16:45:00 +0000

Type Values Removed Values Added
Description Lite XL versions 2.1.8 and prior contain a vulnerability in the system.exec function, which allowed arbitrary command execution through unsanitized shell command construction. This function was used in project directory launching (core.lua), drag-and-drop file handling (rootview.lua), and the “open in system” command in the treeview plugin (treeview.lua). If an attacker could influence input to system.exec, they might execute arbitrary commands with the privileges of the Lite XL process.
Title CVE-2025-12121
References

cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published: 2025-11-20T16:39:05.297Z

Updated: 2025-11-20T18:10:14.597Z

Reserved: 2025-10-23T18:11:28.957Z

Link: CVE-2025-12121

cve-icon Vulnrichment

Updated: 2025-11-20T18:10:06.808Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-11-20T17:15:48.787

Modified: 2025-11-21T15:13:13.800

Link: CVE-2025-12121

cve-icon Redhat

No data.