VYPR
Medium severityGHSA Advisory· Published Jun 22, 2026· Updated Jun 23, 2026

CVE-2026-53632

CVE-2026-53632

Description

launch-editor allows users to open files with line numbers in editor from Node.js. Prior to 2.14.1, the launch-editor NPM package accesses arbitrary paths including Windows UNC paths. When a UNC path is opened, Windows automatically attempts NTLM authentication to the remote host, causing the user’s NTLMv2 password hash to be leaked to an attacker-controlled SMB server. This can result in credential compromise through offline hash cracking. This vulnerability is fixed in 2.14.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
launch-editornpm
< 2.14.12.14.1
vitenpm
>= 8.0.0, < 8.0.168.0.16
vitenpm
>= 7.0.0, < 7.3.57.3.5
vitenpm
< 6.4.36.4.3
vite-plusnpm
< 0.1.240.1.24

Affected products

12

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.