muffin.ink · Apr 23, 2026
Every version of Scratch is vulnerable to arbitrary code execution
0Sign in to vote or save
This site does not allow itself to be embedded. You can still read it on the original site — the toolbar below keeps your place in the directory.
Update May 21, 2026: The vulnerability was fixed on the website a bit ago. They also released v3.32.0 of Scratch Desktop, which is intended to fix this bug. Update May 6, 2026: Scratch expanded their server-side filtering to hopefully prevent uploading new malicious projects to the Scratch website, with more permanent fixes in various stages of development. No fix is available for Scratch Desktop…
Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.