CVE-2024-52011EPSS p33.8%

CVE-2024-52011CVE-2024-52011

Description

launch-editor allows users to open files with line numbers in editor from Node.js. Prior to version 2.9.0, due to the insufficient sanitization of the `file` argument in the `launchEditor`, an attacker can execute arbitrary commands on Windows by supplying a filename that contains special characters. This issue has been fixed in the `launch-editor` version 2.9.0, corresponding to vite version 5.4.9.

Scoring

EPSS0.42% probability of exploitation · percentile 33.8% · 2026-06-19T12:03:05Z
Last modified2026-06-02

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2026-49492
CVE
CVE-2026-48569
CVE
CVE-2026-34714
CVE
CVE-2025-65716
CVE
Vite Vitejs Improper Access Control Vulnerability
CVE
CVE-2026-21518
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.