CVE-2026-59561: Command Injection
Sakura Editor provided by Sakura Editor Development Community contains an OS command injection vulnerability. If a victim user is directed to edit a file in a crafted directory, arbitrary OS command may be executed on the user's PC when the user invokes "Open Terminal".
Affected Software
Event History
Frequently Asked Questions
What must an attacker do to exploit this issue?
The attacker must cause the victim to edit a file located in a crafted directory. Code execution occurs only when the victim then invokes the editor's "Open Terminal" function.
Is this remotely exploitable without user involvement?
No. The supplied vector indicates local access and required user interaction: the victim must be directed to the crafted directory, edit a file there, and use "Open Terminal."
Which versions should be updated?
The provided release reference identifies version v2.4.3, but the affected-version range is not included. Verify your installed Sakura Editor version against the vendor advisory and update to the release that addresses the issue.