Lilypond is a specialized music-notation and engraving software that processes textual score descriptions and generates rendered output, presenting a document-processing attack surface. Its observed vulnerability profile centers on argument injection and output-handling weaknesses that arise from the software's command-invocation and downstream-component integration patterns.
The number and severity of CVEs published that impact products developed by Lilypond over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-10992CRITICAL lilypond-invoke-editor in LilyPond 2.19.80 does not validate strings before launching the program specified by the BROWSER environment variable, which allows remote attackers to co | May 11, 2018 | 9.8 | 28 | NO | NO |
CVE-2017-17523HIGH lilypond-invoke-editor in LilyPond 2.19.80 does not validate strings before launching the program specified by the BROWSER environment variable, which allows remote attackers to co | Dec 11, 2017 | 8.8 | 28 | NO | NO |
CVE-2020-17354HIGH LilyPond before 2.24 allows attackers to bypass the -dsafe protection mechanism via output-def-lookup or output-def-scope, as demonstrated by dangerous Scheme code in a .ly file th | Apr 15, 2023 | 8.6 | 27 | NO | NO |
CVE-2020-17353CRITICAL scm/define-stencil-commands.scm in LilyPond through 2.20.0, and 2.21.x through 2.21.4, when -dsafe is used, lacks restrictions on embedded-ps and embedded-svg, as demonstrated by i | Aug 5, 2020 | 9.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lilypond.
Media articles that mention a CVE ID that affects a product developed by Lilypond — matched by CVE ID, not by vendor name.