Out-of-bounds read in Sakura Editor - #VU145343
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to out-of-bounds read in GetLengthByMode in CClipboard.cpp when processing crafted clipboard data through a WSH macro. A remote attacker can trick the victim into running a crafted WSH macro to cause a denial of service.
Exploitation requires a WSH JScript macro that invokes Editor.GetClipboardByFormat(fmt, mode, 4).