Description
Aegisub is a cross-platform advanced subtitle editor. From 3.2.0 to 3.4.2, Aegisub automatically loads Automation scripts referenced by `Automation Scripts` metadata in `ASS` subtitle projects without asking whether the user trusts the scripts or their authors. An attacker can distribute a crafted `ASS` file together with a referenced malicious Automation script, and opening the `AS`  file executes arbitrary code with the privileges of the Aegisub process. From 3.4.0 to 3.4.2, inconsistent handling of embedded `NUL` characters between extension validation and filesystem operations additionally allows a crafted `ASS/Lua` polyglot to reference and execute itself as a single-file variant. The vulnerability is fixed in Aegisub 3.5.0.
Published: 2026-10-09
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: Arbitrary code execution
Action: Immediate Patch
AI Analysis

Impact

Aegisub versions 3.2.0 through 3.4.2 automatically load Automation scripts referenced in the ASI subtitle metadata without user confirmation. A crafted subtitle file can reference a malicious Automation script, which is then executed with the same privileges as the Aegisub process. The vulnerability also permits script self‑referencing via NUL characters in 3.4.0–3.4.2, enabling a single‑file polyglot to run itself. The flaw is a classic file‑based code execution scenario governed by CWE‑158 and CWE‑829.

Affected Systems

The affected vendors and products are TypesettingTools Aegisub versions 3.2.0 through 3.4.2. The issue is resolved in version 3.5.0. No other product variants are listed as affected.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity, while the EPSS score is not available, making it unclear how frequently the flaw is attempted in practice. The vulnerability is not listed in the CISA KEV catalog, suggesting no known public exploits yet. The attack requires the victim to open a malicious ASI file, meaning the threat is limited to environments where users unknowingly load such files. Nevertheless, once a user launches the file, arbitrary code runs with the Aegisub process privileges, providing full control over the local system.

Generated by OpenCVE AI on October 9, 2026 at 22:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Aegisub 3.5.0 or later to eliminate the automatic script execution flaw
  • Configure Aegisub to prompt for confirmation before loading Automation scripts, if the option is available
  • Remove or quarantine any Automation scripts that are not from trusted sources before opening subtitle files

Generated by OpenCVE AI on October 9, 2026 at 22:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 21:00:00 +0000

Type Values Removed Values Added
Description Aegisub is a cross-platform advanced subtitle editor. From 3.2.0 to 3.4.2, Aegisub automatically loads Automation scripts referenced by `Automation Scripts` metadata in `ASS` subtitle projects without asking whether the user trusts the scripts or their authors. An attacker can distribute a crafted `ASS` file together with a referenced malicious Automation script, and opening the `AS`  file executes arbitrary code with the privileges of the Aegisub process. From 3.4.0 to 3.4.2, inconsistent handling of embedded `NUL` characters between extension validation and filesystem operations additionally allows a crafted `ASS/Lua` polyglot to reference and execute itself as a single-file variant. The vulnerability is fixed in Aegisub 3.5.0.
Title Aegisub executes arbitrary code through automatically loaded Automation scripts
Weaknesses CWE-158
CWE-829
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-09T20:37:58.321Z

Reserved: 2026-09-16T16:22:31.542Z

Link: CVE-2026-92705

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T21:17:06.360

Modified: 2026-10-09T21:17:06.360

Link: CVE-2026-92705

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T22:30:13Z

Weaknesses
  • CWE-158

    Improper Neutralization of Null Byte or NUL Character

  • CWE-829

    Inclusion of Functionality from Untrusted Control Sphere