Stack-based buffer overflow in Sakura Editor - #VU145345

 

Stack-based buffer overflow in Sakura Editor - #VU145345

Published: August 25, 2026


Vulnerability identifier: #VU145345
CSH Severity: Medium
CVSS v4: 5.6 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-121
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to stack-based buffer overflow in Command_TagsMake command line construction in CViewCommander_TagJump.cpp when building the ctags execution command line. A local user can provide overly long tag options to cause a denial of service.

The advisory notes that current input constraints prevent overflow in the described configuration, but the command construction uses an unbounded wrapper.


Affected software

Sakura Editor

Remediation

Install security update from vendor's website.

Sakura Editor - update to 2.4.3

External References

Related Security Bulletins