CVE-2026-59561: Sakura Editor Development Community Sakura Editor
High severity, CVSS 8.4. EPSS: 1.1% chance of exploitation in the next 30 days.
Sakura Editor provided by Sakura Editor Development Community contains an OS command injection vulnerability. If a victim user is directed to edit a file in a crafted directory, arbitrary OS command may be executed on the user's PC when the user invokes "Open Terminal".
Affected products
- Sakura Editor Development Community Sakura Editor: before 2.4.3 (fixed in 2.4.3)
Published 2026-08-24. Last modified 2026-08-28.