Arbitrary Command Execution Vulnerability in Lite XL by Lite XL
CVE-2025-12121

7.3HIGH

Key Information:

Vendor

Lite Xl

Status
Vendor
CVE Published:
20 November 2025

What is CVE-2025-12121?

Lite XL versions up to 2.1.8 have a significant vulnerability in the system.exec function, which allows attackers to execute arbitrary commands through unsanitized inputs. This vulnerability primarily affects functionalities tied to project directory launching, drag-and-drop file handling, and the 'open in system' command via the treeview plugin. If exploited, an attacker could manipulate inputs to system.exec, leading to the execution of unauthorized commands with the privileges of the Lite XL process, thereby posing serious security risks.

Affected Version(s)

Lite XL 2.1.8 and earlier

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-12121 : Arbitrary Command Execution Vulnerability in Lite XL by Lite XL