Junglewise Threat Intelligence

CVE-2026-56137: Gotcha Gotcha Games RPG MAKER OS command injection in save-file loading

CVE-2026-56137 · Severity: high · CVSS 7.8 · Published 2026-06-30

Executive brief

RPG MAKER MV and MZ are popular game development tools used to create and play role-playing games. A security flaw allows an attacker to execute malicious commands on a user's computer if the user is tricked into loading a specially crafted save-file. This could lead to a full system compromise, data theft, or the installation of malware.

Technical details

An OS command injection vulnerability (CWE-78) exists in RPG MAKER MV and MZ due to improper neutralization of special elements within game save data. The vulnerability is triggered when the application's 'save data' facility processes a specially crafted file, failing to sanitize inputs before they are used in a context that allows command execution. An attacker must provide a malicious save-file to a user and convince them to load it (User Interaction required). Successful exploitation allows for arbitrary code execution with the privileges of the application. As of the advisory date, the developer recommends a workaround of only loading trusted save files created through personal gameplay.

Affected products

  • Gotcha Gotcha Games Inc. RPG MAKER MV 1.6.3 and earlier
  • Gotcha Gotcha Games Inc. RPG MAKER MZ 1.10.0 and earlier

Timeline

  • 2026-06-30: advisory: JPCERT/CC and vendor published advisories
  • 2026-06-30: disclosed

References