{"id":"CVE-2022-29351","details":"An arbitrary file upload vulnerability in the file upload module of Tiddlywiki5 v5.2.2 allows attackers to execute arbitrary code via a crafted SVG file. Note: The vendor argues that this is not a legitimate issue and there is no vulnerability here.","modified":"2026-08-27T03:50:20.519258125Z","published":"2022-05-16T13:28:55Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/29xxx/CVE-2022-29351.json","cna_assigner":"mitre","isDisputed":true},"references":[{"type":"WEB","url":"https://www.youtube.com/watch?v=F_DBx4psWns"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/29xxx/CVE-2022-29351.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-29351"},{"type":"PACKAGE","url":"https://github.com/Jermolene/TiddlyWiki5"},{"type":"PACKAGE","url":"https://github.com/jimcola99/corruptsvgfile"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/TiddlyWiki/TiddlyWiki5","events":[{"introduced":"76236f5ebe8f646cfdea59a58340892a8d777a3f"},{"last_affected":"76236f5ebe8f646cfdea59a58340892a8d777a3f"}],"database_specific":{"extracted_events":[{"introduced":"5.2.2"},{"last_affected":"5.2.2"}],"source":"CPE_STRING","cpe":"cpe:2.3:a:tiddlywiki:tiddlywiki5:5.2.2:*:*:*:*:*:*:*"}}],"versions":["5.2.2","v5.2.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-29351.json"}}],"schema_version":"1.9.0"}