Sublime Text is a lightweight code editor with a modest but notable vulnerability footprint centered on its core editor product, where disclosures have involved uncontrolled search-path issues and memory-buffer boundary violations. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sublimetext over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-65741CRITICAL Sublime Text 3 Build 3208 or prior for MacOS is vulnerable to Dylib Injection. An attacker could compile a .dylib file and force the execution of this library in the context of the | Dec 9, 2025 | 9.8 | 29 | NO | NO |
CVE-2019-9116HIGH DLL hijacking is possible in Sublime Text 3 version 3.1.1 build 3176 on 32-bit Windows platforms because a Trojan horse api-ms-win-core-fibers-l1-1-1.dll or api-ms-win-core-localiz | Feb 25, 2019 | 7.8 | 25 | NO | NO |
CVE-2017-8368HIGH Sublime Text 3 Build 3126 allows user-assisted attackers to cause a denial of service or possibly have unspecified other impact via a crafted .mkv file. One threat model is a victi | Jul 5, 2017 | 7.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sublimetext.
Media articles that mention a CVE ID that affects a product developed by Sublimetext — matched by CVE ID, not by vendor name.