Published:2026/08/24  Last Updated:2026/08/24

JVN#74538868
Sakura Editor vulnerable to OS command injection

Overview

Sakura Editor provided by Sakura Editor Development Community contains an OS command injection vulnerability.

Products Affected

  • Sakura Editor versions prior to v2.4.3

Description

Sakura Editor provided by Sakura Editor Development Community has a functionality "Open Terminal".
It does not neutralize the string which represents the current directory (the directory where the editing file is located).

  • OS command injection (CWE-78)
    • CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Base Score 8.4
    • CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Base Score 7.8
    • CVE-2026-59561

Impact

If a victim user is directed to edit a file in a crafted directory, arbitrary OS command may be executed on the user's PC when the user invokes "Open Terminal".

Solution

Update the Software
Update the software to the latest version according to the information provided by the developer.

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Credit

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE CVE-2026-59561
JVN iPedia JVNDB-2026-000115