CRITICALVulnerability
CVE-2026-75357
An issue in Bilibili Desktop v.1.17.9 allows a remote attacker to execute arbitrary code via the bili-inject.js and bili-bridge.js components.
Properties
- severity
- CRITICAL
- score
- 9.8
- epss_score
- 0.00635
- cve_id
- CVE-2026-75357
- vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- published_at
- 2026-08-27T17:19:58.993
- last_modified
- 2026-09-01T20:17:22.657
- epss_percentile
- 0.48178
Related Entities (3)
ENRICHED_BY (1)
→[Source]FIRST EPSS
HAS_WEAKNESS (1)
→[Weakness]Improper Control of Generation of Code ('Code Injection')
DESCRIBED_BY (1)
→[Source]NVD
Explore deeper with Ninja Signal's threat intelligence graph