CVE-2020-37040: Code::blocks

High severity, CVSS 8.4. EPSS: 0.2% chance of exploitation in the next 30 days.

Code Blocks 17.12 contains a local buffer overflow vulnerability that allows attackers to execute arbitrary code by crafting a malicious file name with Unicode characters. Attackers can trigger the vulnerability by pasting a specially crafted payload into the file name field during project creation, potentially executing system commands like calc.exe.

Affected products

Published 2026-01-30. Last modified 2026-06-17.