Executive brief
BBEdit is a popular text editor used by developers for code editing and software development. A vulnerability in its Lasso Language Tokenizer component can cause the application to enter an infinite loop when processing specially crafted input, resulting in a denial of service that freezes the editor and impacts developer productivity.
Technical details
A Denial of Service vulnerability exists in the Lasso Language Tokenizer component of BBEdit up to version 15.5.5. The vulnerability is triggered by manipulation of an unknown function within the tokenizer, leading to an infinite loop condition. The attack vector is remote and does not require authentication or special privileges. An attacker can craft malicious Lasso code that, when opened or processed by BBEdit, causes the application to hang indefinitely. The vulnerability is resolved by upgrading to BBEdit version 16.0 or later.
Affected products
- Bare Bones Software BBEdit up to 15.5.5
Timeline
- 2026-08-31: disclosed