Published:2026/08/24 Last Updated:2026/08/24
JVN#74538868
Sakura Editor vulnerable to OS command injection
Overview
Sakura Editor provided by Sakura Editor Development Community contains an OS command injection vulnerability.
Products Affected
- Sakura Editor versions prior to v2.4.3
Description
Sakura Editor provided by Sakura Editor Development Community has a functionality "Open Terminal".
It does not neutralize the string which represents the current directory (the directory where the editing file is located).
- OS command injection (CWE-78)
- CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Base Score 8.4
- CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Base Score 7.8
- CVE-2026-59561
Impact
If a victim user is directed to edit a file in a crafted directory, arbitrary OS command may be executed on the user's PC when the user invokes "Open Terminal".
Solution
Update the Software
Update the software to the latest version according to the information provided by the developer.
Vendor Status
| Vendor | Link |
| Sakura Editor Development Community | Release v2.4.3 ยท sakura-editor (Text in Japanese) |
| SAKURA Editor vulnerable to OS command injection (JVN#74538868) |
References
JPCERT/CC Addendum
Vulnerability Analysis by JPCERT/CC
Credit
Other Information
| JPCERT Alert |
|
| JPCERT Reports |
|
| CERT Advisory |
|
| CPNI Advisory |
|
| TRnotes |
|
| CVE |
CVE-2026-59561 |
| JVN iPedia |
JVNDB-2026-000115 |