peter bassill · operator
$ cve CVE-2020-11722 JSON

CVE-2020-11722

9.8
CRITICAL · CVSS 3.1 · EPSS 3.9% (pctl 90)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

Dungeon Crawl Stone Soup (aka DCSS or crawl) before 0.25 allows remote attackers to execute arbitrary code via Lua bytecode embedded in an uploaded .crawlrc file.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.89% — more likely to be exploited than 90% of all CVEs
WeaknessCWE-434
On CISA KEVno
Public exploitnone known
Published2020-04-12
Last modified2026-06-17

Affected (1)

VendorProduct
dungeon crawl stone soup projectdungeon crawl stone soup

References

→ the Explorer  ·  watch your stack  ·  NVD