Unity3d is best known for its widely used game engine and development editor, where its vulnerability footprint centers on the Unity Editor product and recurs through input-validation and OS command-injection weaknesses that reflect the editor's role in processing assets and invoking build toolchains. Current exploitation activity, severity outcomes, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Unity3d over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-59489HIGH Unity Runtime before 2025-10-02 on Android, Windows, macOS, and Linux allows argument injection that can result in loading of library code from an unintended location. If an applic | Oct 3, 2025 | 8.4 | 32 | NO | NO |
CVE-2017-12939CRITICAL A Remote Code Execution vulnerability was identified in all Windows versions of Unity Editor, e.g., before 5.3.8p2, 5.4.x before 5.4.5p5, 5.5.x before 5.5.4p3, 5.6.x before 5.6.3p1 | Aug 18, 2017 | 9.8 | 32 | NO | NO |
CVE-2019-9197HIGH The com.unity3d.kharma protocol handler in Unity Editor 2018.3 allows remote attackers to execute arbitrary code. | Dec 31, 2019 | 8.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Unity3d.
Media articles that mention a CVE ID that affects a product developed by Unity3d — matched by CVE ID, not by vendor name.