← Back to browse
·
API
CVE-2022-41138
Severity
CRITICAL
CVSS
9.8
EPSS
0.01804
Risk score
39.83
CISA KEV
No
PoC
No
Published
2022-09-20
Modified
2025-05-29
First seen
2026-08-07
Aliases
EUVD-2022-44379, GHSA-56CX-5F5P-V4RV
Products
n/a:n/a n/a
Sources
euvd
EUVD-2022-44379
Description
In Zutty before 0.13, DECRQSS in text written to the terminal can achieve arbitrary code execution.
References
https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-44379
https://github.com/tomszilagyi/zutty/commit/bde7458c60a7bafe08bbeaafbf861eb865edfa38
https://bugs.gentoo.org/868495
https://github.com/tomszilagyi/zutty/compare/0.12...0.13
https://security.gentoo.org/glsa/202209-25