{"id":"CVE-2025-12120","summary":"CVE-2025-12120","details":"Lite XL versions 2.1.8 and prior automatically execute the .lite_project.lua file when opening a project directory, without prompting the user for confirmation. The .lite_project.lua file is intended for project-specific configuration but can contain executable Lua logic. This behavior could allow execution of untrusted Lua code if a user opens a malicious project, potentially leading to arbitrary code execution with the privileges of the Lite XL process.","modified":"2026-08-12T03:51:38.552079296Z","published":"2025-11-20T16:38:29.108Z","database_specific":{"cna_assigner":"certcc","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/12xxx/CVE-2025-12120.json"},"references":[{"type":"WEB","url":"https://kb.cert.org/vuls/id/579478"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/12xxx/CVE-2025-12120.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-12120"},{"type":"FIX","url":"https://github.com/lite-xl/lite-xl/pull/2164"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/lite-xl/lite-xl","events":[{"introduced":"0af4dae0e2748d6afe7bded41c13d96f627cb520"},{"last_affected":"0af4dae0e2748d6afe7bded41c13d96f627cb520"}],"database_specific":{"extracted_events":[{"introduced":"2.1.8 and earlier"},{"last_affected":"2.1.8 and earlier"},{"introduced":"0"},{"last_affected":"2.1.8"}],"source":["AFFECTED_FIELD","CPE_RANGE"],"cpe":"cpe:2.3:a:lite-xl:lite_xl:*:*:*:*:*:*:*:*"}}],"versions":["2.1.8 and earlier","v2.1.8"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-12120.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"}]}