CVE-2026-59561
Received Received - Intake

OS Command Injection in Sakura Editor

Vulnerability report for CVE-2026-59561, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-24

Last updated on: 2026-08-24

Assigner: JPCERT/CC

Description

Sakura Editor provided by Sakura Editor Development Community contains an OS command injection vulnerability. If a victim user is directed to edit a file in a crafted directory, arbitrary OS command may be executed on the user's PC when the user invokes "Open Terminal".

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-24
Last Modified
2026-08-24
Generated
2026-08-24
AI Q&A
2026-08-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
sakura_editor_development_community sakura_editor 2.4.3
sakura_editor_development_community sakura_editor to 2.4.3 (exc)
sakura_editor_development_community sakura_editor 2.4.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-78 The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Sakura Editor has an OS command injection flaw in its 'Open Terminal' feature. If a user opens a file in a specially crafted directory, arbitrary commands may execute on their PC when they use the 'Open Terminal' option.

Detection Guidance

Check if Sakura Editor version is below 2.4.3 by running the editor and checking the version in the about section. Inspect directories where files are edited for suspicious filenames or paths that may contain command-like strings.

Impact Analysis

Attackers could trick users into opening files in malicious directories, leading to unauthorized command execution. This could allow data theft, system compromise, or further attacks on the user's PC.

Compliance Impact

This vulnerability could potentially violate compliance with GDPR and HIPAA due to its high impact on confidentiality, integrity, and availability of user data. Arbitrary OS command execution may lead to unauthorized access, data breaches, or data exfiltration, which are critical violations under these regulations.

Mitigation Strategies

Update Sakura Editor to version 2.4.3 or later immediately. Avoid opening files from untrusted directories or sources. Disable the Open Terminal feature if not required.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-59561. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart