An issue in Bilibili Desktop v.1.17.9 allows a remote attacker to execute arbitrary code via the bili-inject.js and bili-bridge.js components.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-27 17:19
Updated : 2026-09-01 20:17
NVD link : CVE-2026-75357
Mitre link : CVE-2026-75357
CVE.ORG link : CVE-2026-75357
JSON object : View
Products Affected
No product.
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
