VDB

CVE-2022-40764

CVE-2022-40764 PUBLISHED CVSS 7.800000190734863 HIGH

Snyk CLI before 1.996.0 allows arbitrary command execution, affecting Snyk IDE plugins and the snyk npm package. Exploitation could follow from the common practice of viewing untrusted files in the Visual Studio Code editor, for example. The original demonstration was with shell metacharacters in the vendor.json ignore field, affecting snyk-go-plugin before 1.19.1. This affects, for example, the Snyk TeamCity plugin (which does not update automatically) before 20220930.142957.

EPSS 0.57% · 46.0th percentile

Risk Scores

CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.57%
46.0th percentile

Affected Products

VendorProductVersions
npmsnyk-go-plugin0
n/an/an/a
snykgolang_cli0
snykcli0
npmsnyk0

Timeline

  • Oct 3, 2022 CVE Published
  • Oct 4, 2022 EPSS Score
  • Oct 6, 2022 CVE Updated
  • Nov 18, 2022 EPSS Score
  • Feb 15, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 1, 2023 EPSS Score
  • Jun 29, 2023 EPSS Score
  • Aug 13, 2023 EPSS Score
  • Sep 27, 2023 EPSS Score
  • Nov 10, 2023 EPSS Score
  • Feb 8, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›