CVE-2025-12120

Name
CVE-2025-12120
Description
Lite XL versions 2.1.8 and prior automatically execute the .lite_project.lua file when opening a project directory, without prompting the user for confirmation. The .lite_project.lua file is intended for project-specific configuration but can contain executable Lua logic. This behavior could allow execution of untrusted Lua code if a user opens a malicious project, potentially leading to arbitrary code execution with the privileges of the Lite XL process.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
cret@cert.org https://github.com/lite-xl/lite-xl/pull/2164
cret@cert.org https://kb.cert.org/vuls/id/579478

Match rules

CPE URI Source package Min version Max version
lite-xl == 2.1.8 and earlier == None

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
lite-xl edge-community 2.1.8-r1 Sodface <sod@sodface.com> possibly vulnerable
lite-xl edge-community 2.1.8-r0 Sodface <sod@sodface.com> possibly vulnerable
lite-xl edge-community 2.1.7-r0 Sodface <sod@sodface.com> possibly vulnerable
lite-xl edge-community 2.1.6-r0 Sodface <sod@sodface.com> possibly vulnerable
lite-xl 3.22-community 2.1.8-r0 Sodface <sod@sodface.com> possibly vulnerable
lite-xl 3.22-community 2.1.7-r0 Sodface <sod@sodface.com> possibly vulnerable
lite-xl 3.22-community 2.1.6-r0 Sodface <sod@sodface.com> possibly vulnerable