peter bassill · operator
$ cve CVE-2023-32571 JSON

CVE-2023-32571

9.8
CRITICAL · CVSS 3.1 · EPSS 34.9% (pctl 98)

Patch early

EPSS 34.9% — above the 10% action threshold.

Description

Dynamic Linq 1.0.7.10 through 1.2.25 before 1.3.0 allows attackers to execute arbitrary code and commands when untrusted input to methods including Where, Select, OrderBy is parsed.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS34.9% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-697
On CISA KEVno
Public exploitnone known
Published2023-06-22
Last modified2026-06-17

Affected (1)

VendorProduct
dynamic-linqlinq

References

→ the Explorer  ·  watch your stack  ·  NVD