Vulnerability Description
RPG MAKER MV and MZ provided by Gotcha Gotcha Games Inc. contain an OS command injection vulnerability. If a user loads a specially crafted save-file, arbitrary OS command may be executed.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://jvn.jp/en/jp/JVN69681784/
- https://rpgmakerofficial.com/en/news/4188/
- https://rpgmakerofficial.com/news/4183/
FAQ
What is CVE-2026-56137?
CVE-2026-56137 is a vulnerability with a CVSS score of 7.8 (HIGH). RPG MAKER MV and MZ provided by Gotcha Gotcha Games Inc. contain an OS command injection vulnerability. If a user loads a specially crafted save-file, arbitrary OS command may be executed.
How severe is CVE-2026-56137?
CVE-2026-56137 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-56137?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.