CVE-2022-3133

HIGH

drawio < 20.3.0 - OS Command Injection

Title source: llm
STIX 2.1

Description

OS Command Injection in GitHub repository jgraph/drawio prior to 20.3.0.

References (2)

Core 2
Core References
Exploit, Patch, Third Party Advisory x_refsource_confirm
https://huntr.dev/bounties/2d93052f-efc6-4647-9a6d-8b08dc251223

Scores

CVSS v3 7.8
EPSS 0.0134
EPSS Percentile 67.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (1)
diagrams/drawio < 20.3.0
Published Sep 09, 2022
Tracked Since Feb 18, 2026