Impact
The vulnerability is an OS command injection flaw in Sakura Editor. When a user opens a file from a directory crafted by an attacker, the application performs command execution through the built‑in "Open Terminal" feature, allowing arbitrary OS commands to run with the user's privileges. This matches CWE‑78 and could result in full compromise of the affected machine.
Affected Systems
Affected parties include users of Sakura Editor from the Sakura Editor Development Community. The CVE data does not specify affected versions.
Risk and Exploitability
The CVSS score of 8.4 classifies this as a High‑severity flaw. Although EPSS data is not available, the lack of a KEV listing suggests no known widespread exploitation yet, yet the exploit path only requires a local user to open a terminal after visiting a malicious directory. Administrators should treat this as a likely local code execution risk and apply the patch promptly.
OpenCVE Enrichment