Medium severityGHSA Advisory· Published Jun 22, 2026· Updated Jun 23, 2026
CVE-2026-53632
CVE-2026-53632
Description
launch-editor allows users to open files with line numbers in editor from Node.js. Prior to 2.14.1, the launch-editor NPM package accesses arbitrary paths including Windows UNC paths. When a UNC path is opened, Windows automatically attempts NTLM authentication to the remote host, causing the user’s NTLMv2 password hash to be leaked to an attacker-controlled SMB server. This can result in credential compromise through offline hash cracking. This vulnerability is fixed in 2.14.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
launch-editornpm | < 2.14.1 | 2.14.1 |
vitenpm | >= 8.0.0, < 8.0.16 | 8.0.16 |
vitenpm | >= 7.0.0, < 7.3.5 | 7.3.5 |
vitenpm | < 6.4.3 | 6.4.3 |
vite-plusnpm | < 0.1.24 | 0.1.24 |
Affected products
12- Range: <= 0.1.23
- osv-coords11 versionspkg:apk/chainguard/arangodb-3.11pkg:apk/chainguard/arangodb-3.12pkg:apk/chainguard/argo-workflows-ui-3.6pkg:apk/chainguard/gitlab-rails-ce-fips-19.2pkg:apk/chainguard/langfuse-2-workerpkg:apk/chainguard/langfuse-fips-2-workerpkg:apk/chainguard/nextcloud-server-33pkg:apk/chainguard/nextcloud-server-34pkg:apk/wolfi/nextcloud-server-33pkg:rpm/opensuse/agama-web-ui&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/agama-web-ui&distro=openSUSE%20Tumbleweed
< 3.11.14.5-r6+ 10 more
- (no CPE)range: < 3.11.14.5-r6
- (no CPE)range: < 3.12.9.4-r19
- (no CPE)range: < 3.6.19-r7
- (no CPE)range: < 19.2.1-r1
- (no CPE)range: < 2.95.12-r32
- (no CPE)range: < 2.95.12-r35
- (no CPE)range: < 33.0.6-r2
- (no CPE)range: < 34.0.1-r9
- (no CPE)range: < 33.0.6-r2
- (no CPE)range: < 17+673.b97ba64d6-160000.12.1
- (no CPE)range: < 24+0.a836cced5-52.1
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.