Adobe Animate OS Command Injection Vulnerability Allowing Arbitrary Code Execution

Vulnerability

A vulnerability in Adobe Animate related to improper neutralization of special elements used in operating system commands has been identified. This OS command injection vulnerability could lead to arbitrary code execution within the context of the current user. Exploitation requires user interaction, as a victim must open a malicious file. The vulnerability affects Adobe Animate 2023 versions through 23.0.15 and Adobe Animate 2024 versions through 24.0.13 on both Windows and macOS.

Impact

Successful exploitation of this vulnerability allows for arbitrary code execution on the affected system, executed with the privileges of the current user.

Remediation

Users are advised to update Adobe Animate to version 23.0.16 for the 2023 release or version 24.0.14 for the 2024 release. These updates are available through the Adobe Download Center. For IT administrators managing Creative Cloud applications, the Admin Console can be used to deploy these updates to end users.

Added: Jul 15, 2026, 5:20 AM
Updated: Jul 15, 2026, 5:20 AM

Vulnerability Rating

Custom Algorithm
spread
5.4
impact
10.0
exploitability
4.2
remediation
7.7
relevance
9.6
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.