ZDI-26-748: Luxion KeyShot BIP File Parsing Uncontrolled Search Path Element Remote Code Execution Vulnerability
ZDI reports a Luxion KeyShot BIP parsing flaw that can run code if a user opens a malicious file.
ZDI-26-748 covers an uncontrolled search path element in Luxion KeyShot's BIP file parser that can let a remote attacker execute arbitrary code. The target must open a malicious file or visit a malicious page. ZDI rated the issue CVSS 7.8 and assigned CVE-2026-92202. The advisory does not say the flaw is being exploited.
36