# CVE-2024-52011

## Summary

- **CVE ID:** CVE-2024-52011
- **Severity:** HIGH
- **CVSS Score:** 8.3 (CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)
- **CWE:** CWE-77
- **Published:** Jun 1, 2026
- **Last Modified:** Sep 4, 2026

## Description

launch-editor allows users to open files with line numbers in editor from Node.js. Prior to version 2.9.0, due to the insufficient sanitization of the `file` argument in the `launchEditor`, an attacker can execute arbitrary commands on Windows by supplying a filename that contains special characters. This issue has been fixed in the `launch-editor` version 2.9.0, corresponding to vite version 5.4.9.

## Affected Products

- vitejs — launch-editor (< 2.9.0)
- vitejs — vite (< 5.4.9)

## References

- [CNA](https://github.com/vitejs/launch-editor/security/advisories/GHSA-c27g-q93r-2cwf)
- [CNA](https://github.com/vitejs/launch-editor/commit/971291e8a6a91226e1616c5c0ec85423d2d50a5e)
- [redhat-SADP](https://access.redhat.com/security/cve/CVE-2024-52011)
- [redhat-SADP](https://bugzilla.redhat.com/show_bug.cgi?id=2483853)
- [redhat-SADP](https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-52011.json)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:34342)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.51%
- **EPSS Percentile:** 42.6

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-19._