Description
Sakura Editor provided by Sakura Editor Development Community contains an OS command injection vulnerability. If a victim user is directed to edit a file in a crafted directory, arbitrary OS command may be executed on the user's PC when the user invokes "Open Terminal".
Published: 2026-08-24
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Local code execution
Action: Patch Immediately
AI Analysis

Impact

The vulnerability is an OS command injection flaw in Sakura Editor. When a user opens a file from a directory crafted by an attacker, the application performs command execution through the built‑in "Open Terminal" feature, allowing arbitrary OS commands to run with the user's privileges. This matches CWE‑78 and could result in full compromise of the affected machine.

Affected Systems

Affected parties include users of Sakura Editor from the Sakura Editor Development Community. The CVE data does not specify affected versions.

Risk and Exploitability

The CVSS score of 8.4 classifies this as a High‑severity flaw. Although EPSS data is not available, the lack of a KEV listing suggests no known widespread exploitation yet, yet the exploit path only requires a local user to open a terminal after visiting a malicious directory. Administrators should treat this as a likely local code execution risk and apply the patch promptly.

Generated by OpenCVE AI on August 24, 2026 at 06:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Visit the Sakura Editor Development Community website or advisories to locate a patch or update that addresses this flaw.
  • Avoid using the "Open Terminal" feature when editing files from directories that may not be fully trusted.
  • Consider disabling the "Open Terminal" function or restricting user rights if updating is not feasible.

Generated by OpenCVE AI on August 24, 2026 at 06:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 07:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Sakura-editor
Sakura-editor sakura
Vendors & Products Sakura-editor
Sakura-editor sakura

Mon, 24 Aug 2026 07:15:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Sakura Editor Allows Arbitrary Command Execution via Open Terminal

Mon, 24 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Description Sakura Editor provided by Sakura Editor Development Community contains an OS command injection vulnerability. If a victim user is directed to edit a file in a crafted directory, arbitrary OS command may be executed on the user's PC when the user invokes "Open Terminal".
Weaknesses CWE-78
References
Metrics cvssV3_0

{'score': 7.8, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Sakura-editor Sakura
cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-08-24T16:35:38.479Z

Reserved: 2026-07-06T00:19:50.361Z

Link: CVE-2026-59561

cve-icon Vulnrichment

Updated: 2026-08-24T16:35:31.621Z

cve-icon NVD

Status : Deferred

Published: 2026-08-24T05:16:55.090

Modified: 2026-08-28T16:09:10.947

Link: CVE-2026-59561

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T21:11:48Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')