sublimetext records
4 published records for vendor sublimetext.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-427 Uncontrolled Search Path Element2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2024-25255No exploit | Sublime Text 4 was discovered to contain a command injection vulnerability via the New Build System module.CWE-77 | Critical9.8 | — | 1.5% | Nov 11, 2024 |
39Monitor | CVE-2025-65741Proof of concept | Sublime Text 3 Build 3208 or prior for MacOS is vulnerable to Dylib Injection.sublimetext · sublime text 3 · CWE-427 | Critical9.8 | — | 0.5% | Dec 9, 2025 |
31Monitor | CVE-2019-9116No exploit | DLL hijacking is possible in Sublime Text 3 version 3.1.1 build 3176 on 32-bit Windows platforms because a Trojan horse api-ms-win-core-fibesublimetext · sublime text 3 · CWE-427 | High7.8 | — | 1.1% | Feb 25, 2019 |
31Monitor | CVE-2017-8368No exploit | Sublime Text 3 Build 3126 allows user-assisted attackers to cause a denial of service or possibly have unspecified other impact via a craftesublimetext · sublime text 3 · CWE-119 | High7.8 | — | 0.9% | Jul 5, 2017 |
- CVE-2024-2525539Monitor
Sublime Text 4 was discovered to contain a command injection vulnerability via the New Build System module.
CriticalCVSS 9.8No exploitEPSS 1%Nov 11, 2024
- CVE-2025-6574139Monitor
Sublime Text 3 Build 3208 or prior for MacOS is vulnerable to Dylib Injection.
CriticalCVSS 9.8Proof of conceptEPSS 1%sublimetext · sublime text 3Dec 9, 2025
- CVE-2019-911631Monitor
DLL hijacking is possible in Sublime Text 3 version 3.1.1 build 3176 on 32-bit Windows platforms because a Trojan horse api-ms-win-core-fibe
HighCVSS 7.8No exploitEPSS 1%sublimetext · sublime text 3Feb 25, 2019
- CVE-2017-836831Monitor
Sublime Text 3 Build 3126 allows user-assisted attackers to cause a denial of service or possibly have unspecified other impact via a crafte
HighCVSS 7.8No exploitEPSS 1%sublimetext · sublime text 3Jul 5, 2017