RSSAmplifier

muffin.ink · Apr 23, 2026

Every version of Scratch is vulnerable to arbitrary code execution

0
Sign in to vote or save

This site does not allow itself to be embedded. You can still read it on the original site — the toolbar below keeps your place in the directory.

Update May 21, 2026: The vulnerability was fixed on the website a bit ago. They also released v3.32.0 of Scratch Desktop, which is intended to fix this bug. Update May 6, 2026: Scratch expanded their server-side filtering to hopefully prevent uploading new malicious projects to the Scratch website, with more permanent fixes in various stages of development. No fix is available for Scratch Desktop…

Read on muffin.ink

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.