CVE-2025-12121

HIGH

Lite XL < 2.1.8 - OS Command Injection via system.exec Function

Title source: llm
STIX 2.1

Description

Lite XL versions 2.1.8 and prior contain a vulnerability in the system.exec function, which allowed arbitrary command execution through unsanitized shell command construction. This function was used in project directory launching (core.lua), drag-and-drop file handling (rootview.lua), and the “open in system” command in the treeview plugin (treeview.lua). If an attacker could influence input to system.exec, they might execute arbitrary commands with the privileges of the Lite XL process.

References (2)

Core 2
Core References
Exploit, Patch, Third Party Advisory
https://kb.cert.org/vuls/id/579478

Scores

CVSS v3 7.3
EPSS 0.0033
EPSS Percentile 25.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-78
Status published
Products (1)
lite-xl/lite_xl < 2.1.8
Published Nov 20, 2025
Tracked Since Feb 18, 2026