Out-of-bounds write in Sakura Editor - #VU145341

 

Out-of-bounds write in Sakura Editor - #VU145341

Published: August 25, 2026


Vulnerability identifier: #VU145341
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to out-of-bounds write in CImpExpKeyHelp::Import() when importing a crafted keyword help dictionary file. A remote attacker can trick the victim into opening a crafted file to execute arbitrary code.

User interaction is required to import the crafted dictionary file through the keyword help import feature.


Affected software

Sakura Editor

Remediation

Install security update from vendor's website.

Sakura Editor - update to 2.4.2

External References

Related Security Bulletins