CVE-2022-46387

Source
https://cve.org/CVERecord?id=CVE-2022-46387
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-46387.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-46387
Published
2023-03-28T20:15:10.940Z
Modified
2025-11-14T13:54:35.841608Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

ConEmu through 220807 and Cmder before 1.3.21 report the title of the terminal, including control characters, which allows an attacker to change the title and then execute it as commands.

References

Affected packages

Git / github.com/cmderdev/cmder

Affected ranges

Type
GIT
Repo
https://github.com/cmderdev/cmder
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

v1.*
v1.0.0
v1.0.0-beta
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.1.4.1
v1.2
v1.2.9
v1.3.0
v1.3.0-pre
v1.3.1

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-46387.json"