CVE-2022-46997

CRITICAL

Passhunt < commit 54eb987d30ead2b8ebbf1f0b880aa14249323867 - RCE

Title source: llm
STIX 2.1

Description

Passhunt commit 54eb987d30ead2b8ebbf1f0b880aa14249323867 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

Scores

CVSS v3 9.8
EPSS 0.0071
EPSS Percentile 72.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-912
Status published
Products (1)
passhunt_project/passhunt
Published Dec 14, 2022
Tracked Since Feb 18, 2026