peter bassill · operator
$ cve CVE-2022-45063 JSON

CVE-2022-45063

9.8
CRITICAL · CVSS 3.1 · EPSS 5.4% (pctl 92)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

xterm before 375 allows code execution via font ops, e.g., because an OSC 50 response may have Ctrl-g and therefore lead to command execution within the vi line-editing mode of Zsh. NOTE: font ops are not allowed in the xterm default configurations of some Linux distributions.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS5.42% — more likely to be exploited than 92% of all CVEs
WeaknessCWE-77
On CISA KEVno
Public exploitnone known
Published2022-11-10
Last modified2026-06-17

Affected (2)

VendorProduct
fedoraprojectfedora
invisible-islandxterm

References

→ the Explorer  ·  watch your stack  ·  NVD