HIGH

CVE-2022-3008

CVSS v3

8.8

HIGH

EPSS Score

11.9%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

The tinygltf library uses the C library function wordexp() to perform file path expansion on untrusted paths that are provided from the input file. This function allows for command injection by using backticks. An attacker could craft an untrusted path input that would result in a path expansion. We recommend upgrading to 2.6.0 or past commit 52ff00a38447f06a17eab1caa2cf0730a119c751

Technical details

Published
9/5/2022

Frequently asked questions

What is CVE-2022-3008?

The tinygltf library uses the C library function wordexp() to perform file path expansion on untrusted paths that are provided from the input file. This function allows for command injection by using backticks. An attacker could craft an untrusted path input that would result in a path expansion. We recommend upgrading to 2.6.0 or past commit 52ff00a38447f06a17eab1caa2cf0730a119c751

Is CVE-2022-3008 actively exploited?

Active exploitation of CVE-2022-3008 has not been confirmed. The EPSS score is 11.9%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2022-3008?

CVE-2022-3008 has a CVSS v3 base score of 8.8 (HIGH severity).

Is CVE-2022-3008 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.