Sublime Forum

Vulnerable Inno Setup version used by ST4 build 4200

#1

Hello,

I did not find any /.well-known/security.txt or other security contact information so I assume this is the correct place to post about this:

I noticed that the Sublime Text 4 newest build 4200 is using a rather dated Inno Setup installer version (5.5.9). The version seems to be affected by this CVE that was published last week:
https://nvd.nist.gov/vuln/detail/CVE-2025-15595

Based on my testing the issue seems to render ST4 vulnerable!

0 Likes