CVE-2026-92705
Received Received - Intake

Arbitrary Code Execution in Aegisub

Vulnerability report for CVE-2026-92705, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: GitHub, Inc.

Description

Aegisub is a cross-platform advanced subtitle editor. From 3.2.0 to 3.4.2, Aegisub automatically loads Automation scripts referenced by `Automation Scripts` metadata in `ASS` subtitle projects without asking whether the user trusts the scripts or their authors. An attacker can distribute a crafted `ASS` file together with a referenced malicious Automation script, and opening the `AS`Β  file executes arbitrary code with the privileges of the Aegisub process. From 3.4.0 to 3.4.2, inconsistent handling of embedded `NUL` characters between extension validation and filesystem operations additionally allows a crafted `ASS/Lua` polyglot to reference and execute itself as a single-file variant. The vulnerability is fixed in Aegisub 3.5.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
TypesettingTools Aegisub >= 3.2.0, < 3.5.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-158 The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes NUL characters or null bytes when they are sent to a downstream component.
CWE-829 The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Aegisub versions 3.2.0 to 3.4.2 automatically load Automation scripts referenced in ASS subtitle projects without user confirmation. An attacker can embed a malicious script in a crafted ASS file, which executes arbitrary code when the file is opened. From 3.4.0 to 3.4.2, a flaw in handling NUL characters allows a polyglot file to execute itself as a single variant.

Detection Guidance

Check Aegisub version installed. If between 3.2.0 and 3.4.2, the system is vulnerable. Review subtitle files for Automation Scripts metadata referencing external scripts.

Impact Analysis

If you open a malicious ASS file, arbitrary code may execute on your system with the same privileges as Aegisub. This could lead to data theft, system compromise, or further malware installation. Users of vulnerable versions are at risk if they open untrusted subtitle files.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, violating GDPR (data protection) or HIPAA (health data privacy) if sensitive information is exposed. Organizations must ensure systems are patched to maintain compliance.

Mitigation Strategies

Upgrade Aegisub to version 3.5.0 or later. Avoid opening untrusted ASS files. Disable automatic script loading if possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-92705. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart