CVE-2026-56137Disclosure

LOWCVSS 8.4 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

RPG MAKER MV and MZ provided by Gotcha Gotcha Games Inc. contain an OS command injection vulnerability. If a user loads a specially crafted save-file, arbitrary OS command may be executed.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-06-30); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-06-30: 2Mentions · 2026-07-02: 1Patch / Workaround · 2026-06-30: 1Technical Details · 2026-06-30: 2Technical Details · 2026-07-02: 106-3007-02
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-06-302
Disclosure2
2026-07-021
Disclosure1
Full discourse3 posts
  • connect24h@connect24h
    Disclosure

    セーブデータを「ただのゲーム進行情報」と見るのは危ない。RPGツクールMV+1.6.3以前/MZ+1.10.0以前でOSコマンドインジェクション、CVE-2026-56137。CVSS+v4.0+8.4、細工されたセーブデータ読込で任意OSコマンド実行の可能性。なんというニッチな報告だ・・・ 業務ではみんな使ってないと思うけど・・・出所不明のセーブデータ・ゲームは読ませないようにね。お子さんに注意したほうが重要かも。うちの子も、この前まで、いろんなMod試してたし。(もっと危ない)https://scan.netsecurity.ne.jp/article/2026/07/02/55615.html #セキュリティ

    Post summary

    The post alerts about a newly disclosed OS command injection vulnerability (CVE‑2026‑56137) in RPG Maker MV/MZ before specified versions, urging users to avoid loading unknown save files or mods.

    02251770
    6.7K followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Disclosure

    #CVE-2026-56137 - #OS Command Injection in RPG Maker MV/MZ. #CVSS 7.8. Loading a malicious save file can execute arbitrary commands. No patch yet. Disable auto-load features. #CVEAlert #infosec #developers #gamedev More detailed info: https://www.valtersit.com/cve/CVE-2026-56137

    Post summary

    CVE‑2026‑56137 is an OS Command Injection in RPG Maker MV/MZ with a CVSS of 7.8; no patch is available yet, and users are advised to disable auto‑load features to mitigate the risk.

    0000064
    967 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-56137 OS Command Injection in RPG MAKER MV and MZ via Malicious Save File https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-56137

    Post summary

    An OS Command Injection vulnerability (CVE-2026-56137) has been disclosed affecting RPG MAKER MV and MZ via malicious save files.

    0000099
    4.1K followersView on X

Explore more