CVE-2023-0341: Editorconfig
High severity, CVSS 7.8. EPSS: 1% chance of exploitation in the next 30 days.
A stack buffer overflow exists in the ec_glob function of editorconfig-core-c before v0.12.6 which allowed an attacker to arbitrarily write to the stack and possibly allows remote code execution. editorconfig-core-c v0.12.6 resolved this vulnerability by bound checking all write operations over the p_pcre buffer.
Affected products
- Editorconfig Editorconfig: before 0.12.6 (fixed in 0.12.6)
Published 2023-02-01. Last modified 2026-06-17.