Impact
Aegisub versions 3.2.0 through 3.4.2 automatically load Automation scripts referenced in the ASI subtitle metadata without user confirmation. A crafted subtitle file can reference a malicious Automation script, which is then executed with the same privileges as the Aegisub process. The vulnerability also permits script self‑referencing via NUL characters in 3.4.0–3.4.2, enabling a single‑file polyglot to run itself. The flaw is a classic file‑based code execution scenario governed by CWE‑158 and CWE‑829.
Affected Systems
The affected vendors and products are TypesettingTools Aegisub versions 3.2.0 through 3.4.2. The issue is resolved in version 3.5.0. No other product variants are listed as affected.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, while the EPSS score is not available, making it unclear how frequently the flaw is attempted in practice. The vulnerability is not listed in the CISA KEV catalog, suggesting no known public exploits yet. The attack requires the victim to open a malicious ASI file, meaning the threat is limited to environments where users unknowingly load such files. Nevertheless, once a user launches the file, arbitrary code runs with the Aegisub process privileges, providing full control over the local system.
OpenCVE Enrichment