CVE-2022-41875
CRITICALOptica < 0.10.2 - Unauthenticated Remote Code Execution via JSON Payload Deserialization
Title source: llmDescription
A remote code execution (RCE) vulnerability in Optica allows unauthenticated attackers to execute arbitrary code via specially crafted JSON payloads. Specially crafted JSON payloads may lead to RCE (remote code execution) on the attacked system running Optica. The vulnerability was patched in v. 0.10.2, where the call to the function `oj.load` was changed to `oj.safe_load`.
References (3)
Core 3
Core References
Third Party Advisory
https://github.com/airbnb/optica/security/advisories/GHSA-cf87-4h6x-phh6
Third Party Advisory
https://github.com/ohler55/oj/blob/develop/pages/Security.md
Release Notes, Vendor Advisory
https://www.rubydoc.info/gems/oj/3.0.2/Oj.safe_load
Scores
CVSS v3
10.0
EPSS
0.0160
EPSS Percentile
72.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-502
Status
published
Products (1)
airbnb/optica
< 0.10.2
Published
Nov 23, 2022
Tracked Since
Feb 18, 2026