PT-2025-46528 · X Lite · X-Lite

Published

2025-11-11

·

Updated

2025-11-20

·

CVE-2025-12120

CVSS v3.1

7.3

High

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Lite XL versions prior to 2.1.9
Description Lite XL automatically executes the .lite project.lua file when opening a project directory without user confirmation. This file is designed for project configuration but can contain executable Lua code. Opening a malicious project could lead to the execution of untrusted Lua code, potentially resulting in arbitrary code execution with the privileges of the Lite XL process.
Recommendations Update Lite XL to version 2.1.9 or later.

Fix

NULL Pointer Dereference

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2026-00071
CVE-2025-12120

Affected Products

X-Lite