CVE-2026-56137
HIGHGotcha Gotcha Games Inc. Rpg Maker MV - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Title source: ruleExploitation Summary
EIP tracks 1 public exploit for CVE-2026-56137. PoCs published by HermesNA-1.
AI-analyzed exploit summary This repository contains an auto-generated stub module for CVE-2026-56137, an OS command injection vulnerability in RPG MAKER MV and MZ. The code includes placeholder logic for target probing but lacks actual exploit implementation or crafted payloads for the save-file command injection.
Description
RPG MAKER MV and MZ provided by Gotcha Gotcha Games Inc. contain an OS command injection vulnerability. If a user loads a specially crafted save-file, arbitrary OS command may be executed.
Exploits (1)
This repository contains an auto-generated stub module for CVE-2026-56137, an OS command injection vulnerability in RPG MAKER MV and MZ. The code includes placeholder logic for target probing but lacks actual exploit implementation or crafted payloads for the save-file command injection.
References (3)
Scores
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H