Arbitrary Command Execution Vulnerability in Lite XL by Lite XL
CVE-2025-12121
What is CVE-2025-12121?
Lite XL versions up to 2.1.8 have a significant vulnerability in the system.exec function, which allows attackers to execute arbitrary commands through unsanitized inputs. This vulnerability primarily affects functionalities tied to project directory launching, drag-and-drop file handling, and the 'open in system' command via the treeview plugin. If exploited, an attacker could manipulate inputs to system.exec, leading to the execution of unauthorized commands with the privileges of the Lite XL process, thereby posing serious security risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Lite XL 2.1.8 and earlier
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
