CVE-2023-40168 is a critical vulnerability affecting TurboWarp Desktop versions prior to 1.8.0, allowing malicious Scratch projects or custom extensions to read arbitrary files from a user's disk and upload them to a remote server. This high-severity flaw (CVSS 6.5) requires only minimal user interaction—opening an untrusted .sb3 file or loading an extension—and could lead to significant data compromise. While the web version is unaffected, users are strongly advised to upgrade to version 1.8.0 or later, or to avoid untrusted sources. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.8.0CPE matchmatch criteria | cpe:2.3:a:turbowarp:turbowarp_desktop:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.