ZDI-26-748: Luxion KeyShot BIP File Parsing Uncontrolled Search Path Element Remote Code Execution Vulnerability
ZDI reports a Luxion KeyShot BIP parsing flaw that can run code if a user opens a malicious file.
ZDI-26-748 covers an uncontrolled search path element in Luxion KeyShot's BIP file parser that can let a remote attacker execute arbitrary code. The target must open a malicious file or visit a malicious page. ZDI rated the issue CVSS 7.8 and assigned CVE-2026-92202. The advisory does not say the flaw is being exploited.
- BIP file parsing flaw allows code execution in Luxion KeyShot.
- Attack needs the user to open a malicious file or page.
- ZDI rates it CVSS 7.8; CVE-2026-92202.
- No active exploitation is mentioned in the advisory.
Vulnerabilities mentionedAll →
- published —
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-92202 | NVD description · AI analysis pending | — | — | — | — | — |
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Luxion KeyShot. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-92202.
This source does not provide full text. Read it at zerodayinitiative.com.