Executive brief
nadesiko3 is a JavaScript-based programming language and IDE used for educational and scripting purposes. An OS command injection vulnerability in the compression/decompression component allows remote attackers to execute arbitrary operating system commands on affected systems, potentially leading to complete system compromise.
Technical details
The vulnerability is a command injection flaw (CWE-78) in the Nako3edit editor component of nadesiko3 PC version v3.3.74 and earlier, specifically in the compression and decompression functionality. An attacker can exploit this vulnerability without authentication to execute arbitrary OS commands and extract the application key. The attack vector is network-based with no preconditions or user interaction required. The vulnerability was fixed in version 3.3.75 and later.
Affected products
- nadesiko nadesiko3 3.3.74 and earlier
Timeline
- 2022-12-05: disclosed
- 2022-12-05: patched: Fixed in version 3.3.75