PatchSiren

TypesettingTools CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH TypesettingTools CVE published 2026-10-09

CVE-2026-92705

Aegisub, a cross-platform advanced subtitle editor, executes arbitrary code through automatically loaded Automation scripts in ASS subtitle projects. This vulnerability exists from version 3.2.0 to 3.4.2 and is fixed in version 3.5.0. Users should assess their exposure and take steps to mitigate the vulnerability. The vulnerability allows for arbitrary code execution with the privileges of the Aegisub pro [truncated]