Libretro develops a modular emulation and game frontend framework, with RetroArch and libretro-common forming the core of a cross-platform architecture designed to support hundreds of legacy game console and arcade emulators. Its sparse vulnerability footprint clusters around memory-safety and command-injection weaknesses, including buffer overflows, out-of-bounds reads and writes, and OS command injection, which reflects the parsing demands of legacy game formats and the native-code execution model underlying the framework. Current severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Libretro over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-9809CRITICAL Out-of-bounds write in cdfs_open_cue_track in libretro libretro-common latest on all platforms allows remote attackers to execute arbitrary code via a crafted .cue file with a file | Sep 1, 2025 | 9.8 | 31 | NO | NO |
CVE-2021-28927HIGH The text-to-speech engine in libretro RetroArch for Windows 1.9.0 passes unsanitized input to PowerShell through platform_win32.c via the accessibility_speak_windows function, whic | Apr 7, 2021 | 7.8 | 27 | NO | NO |
CVE-2025-9136HIGH A flaw has been found in libretro RetroArch 1.18.0/1.19.0/1.20.0. This affects the function filestream_vscanf of the file libretro-common/streams/file_stream.c. This manipulation c | Aug 19, 2025 | 7.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Libretro.
Media articles that mention a CVE ID that affects a product developed by Libretro — matched by CVE ID, not by vendor name.