CVE-2026-75357
largeUnauthenticated Code Injection RCE in Bilibili Desktop 1.17.9
Bilibili Desktop version 1.17.9 contains a code injection vulnerability (CWE-94) in its bili-inject.js and bili-bridge.js components that allows a remote attacker to execute arbitrary code. Per the CVSS 3.1 scoring (AV:N/AC:L/PR:N/UI:N), the issue is exploitable over a network with no privileges or user interaction required. A successful attack grants arbitrary code execution with high impact on confidentiality, integrity, and availability on the affected system. Anyone running Bilibili Desktop 1.17.9 is affected, though the CVE data documents only that specific version and provides no fixed release. As of now there is no public proof of concept, no CISA KEV listing, and no confirmed exploitation in the wild, with EPSS estimating only a 0.6% probability of exploitation in the next 30 days.
What to do: Check the installed Bilibili Desktop version and upgrade to the latest vendor release as soon as a patched build is published, since no fixed version is documented yet. Until then, treat the desktop client as vulnerable and consider restricting its use to trusted content while monitoring for vendor advisories or the emergence of public exploit code. Given the low EPSS score and absence of a known PoC, there is no indication of active targeting at this time.
| Bilibili Desktop | 1.17.9 (the only version documented; other versions may be affected but are not specified) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An issue in Bilibili Desktop v.1.17.9 allows a remote attacker to execute arbitrary code via the bili-inject.js and bili-bridge.js components.
- Weakness
- CWE-94
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.