PT-2025-46528 · X Lite · X-Lite

CVE-2025-12120

·

Published

2025-11-11

·

Updated

2025-11-20

CVSS v3.1

7.3

High

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Lite XL versions prior to 2.1.9
Description Lite XL automatically executes the .lite project.lua file when opening a project directory without user confirmation. This file is designed for project configuration but can contain executable Lua code. Opening a malicious project could lead to the execution of untrusted Lua code, potentially resulting in arbitrary code execution with the privileges of the Lite XL process.
Recommendations Update Lite XL to version 2.1.9 or later.

Exploit

Fix

NULL Pointer Dereference

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-00071
CVE-2025-12120

Affected Products

X-Lite