CVE-2019-9197: UNITY3D Unity Editor

High severity, CVSS 8.8. EPSS: 3.7% chance of exploitation in the next 30 days.

The com.unity3d.kharma protocol handler in Unity Editor 2018.3 allows remote attackers to execute arbitrary code.

Affected products

  • UNITY3D Unity Editor: from 5.6.0, before 5.6.7f1 (fixed in 5.6.7f1); from 2017.4.22, before 2017.4.22f1 (fixed in 2017.4.22f1); from 2018.2.21, before 2018.2.21f1 (fixed in 2018.2.21f1); from 2018.3.7, before 2018.3.7f1 (fixed in 2018.3.7f1); from 2019.1.0, before 2019.1.0b5 (fixed in 2019.1.0b5); from 2019.2.0, before 2019.2.0a7 (fixed in 2019.2.0a7)

Published 2019-12-31. Last modified 2026-06-17.