← Back to CVE List

CVE-2022-33127

Published: 2022-06-23T17:15Z
Last Modified: 2024-11-21T07:07Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The function that calls the diff tool in Diffy 3.4.1 does not properly handle double quotes in a filename when run in a windows environment. This allows attackers to execute arbitrary commands via a crafted string. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt