Skip to main content
HIGH

CVE-2022-45639

CVSS v3

7.8

HIGH

EPSS Score

4.7 %

exploit probability, as of 2026-09-25

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

OS Command injection vulnerability in sleuthkit fls tool 4.11.1 allows attackers to execute arbitrary commands via a crafted value to the m parameter. NOTE: third parties have disputed this because there is no analysis showing that the backtick command executes outside the context of the user account that entered the command line.

Technical details

Published
2023-01-24
Exploit-DB
EDB-51225

Frequently asked questions

What is CVE-2022-45639?

OS Command injection vulnerability in sleuthkit fls tool 4.11.1 allows attackers to execute arbitrary commands via a crafted value to the m parameter. NOTE: third parties have disputed this because there is no analysis showing that the backtick command executes outside the context of the user account that entered the command line.

Is CVE-2022-45639 actively exploited?

Active exploitation of CVE-2022-45639 has not been confirmed. Its EPSS score was 4.7% on 2026-09-25, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2022-45639?

CVE-2022-45639 has a CVSS v3 base score of 7.8 (HIGH severity).

Is CVE-2022-45639 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key