{"id":"CVE-2022-41958","summary":"Deserialization Vulnerability by yaml config input in super-xray","details":"super-xray is a web vulnerability scanning tool. Versions prior to 0.7 assumed trusted input for the program config which is stored in a yaml file. An attacker with local access to the file could exploit this and compromise the program. This issue has been addressed in commit `4d0d5966` and will be included in future releases. Users are advised to upgrade. There are no known workarounds for this issue.","aliases":["GHSA-39pv-4vmj-c4fr"],"modified":"2026-08-12T13:33:29.184960Z","published":"2022-11-25T00:00:00Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-502"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/41xxx/CVE-2022-41958.json"},"references":[{"type":"ADVISORY","url":"https://github.com/4ra1n/super-xray/security/advisories/GHSA-39pv-4vmj-c4fr"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/41xxx/CVE-2022-41958.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-41958"},{"type":"FIX","url":"https://github.com/4ra1n/super-xray/commit/4d0d59663596db03f39d7edd2be251d48b52dcfc"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/4ra1n/super-xray","events":[{"introduced":"0"},{"fixed":"7a1dcf51f741cb65d7a542bf3d31e562287a42bd"},{"fixed":"4d0d59663596db03f39d7edd2be251d48b52dcfc"}],"database_specific":{"cpe":"cpe:2.3:a:super_xray_project:super_xray:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"0.7"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["0.6-beta","0.5-beta","0.4-beta","0.3-beta","0.2-beta","0.1-beta"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-41958.json","vanir_signatures_modified":"2026-08-12T13:33:29Z","vanir_signatures":[{"target":{"file":"src/main/java/com/chaitin/xray/form/LookupConfigForm.java"},"deprecated":false,"digest":{"line_hashes":["201140724825506654566816982559933346228","319639773728655626016946178391904591345","223682944318343984076449579274768184908","87732518419572568206162078245802357736","199126481791449562854203376119927922450","256692695630304253394553988593443679032","18210170398604480612899252284111886614","326272401500660370655465089339934246000","333934407384069787815111895992492796342"],"threshold":0.9},"id":"CVE-2022-41958-3a967684","signature_type":"Line","signature_version":"v1","source":"https://github.com/4ra1n/super-xray/commit/4d0d59663596db03f39d7edd2be251d48b52dcfc"},{"deprecated":false,"digest":{"function_hash":"298172198180111179171800309987526971057","length":447},"id":"CVE-2022-41958-602099bf","signature_type":"Function","signature_version":"v1","source":"https://github.com/4ra1n/super-xray/commit/4d0d59663596db03f39d7edd2be251d48b52dcfc","target":{"file":"src/main/java/com/chaitin/xray/form/MainForm.java","function":"refreshConfig"}},{"deprecated":false,"digest":{"function_hash":"25174956171248500128043481061022443502","length":5406},"id":"CVE-2022-41958-6543698a","signature_type":"Function","signature_version":"v1","source":"https://github.com/4ra1n/super-xray/commit/4d0d59663596db03f39d7edd2be251d48b52dcfc","target":{"file":"src/main/java/com/chaitin/xray/form/MainForm.java","function":"reloadConfig"}},{"digest":{"line_hashes":["95409948778455503071025741182787925458","49254545899382509877748385085243028277","330504218350016407640114522149142818070","197762477653266989479350768195436407366"],"threshold":0.9},"id":"CVE-2022-41958-6a669d5a","signature_type":"Line","signature_version":"v1","source":"https://github.com/4ra1n/super-xray/commit/4d0d59663596db03f39d7edd2be251d48b52dcfc","target":{"file":"src/main/java/com/chaitin/xray/test/Main.java"},"deprecated":false},{"signature_version":"v1","source":"https://github.com/4ra1n/super-xray/commit/4d0d59663596db03f39d7edd2be251d48b52dcfc","target":{"file":"src/main/java/com/chaitin/xray/form/MainForm.java"},"deprecated":false,"digest":{"line_hashes":["16862199755715672136254423359301046594","123983912731503354910811958671819622203","296864937459062579868849255378850963540","34949094517301780867760527519309357758","244202951793215915556975364666569117058","266988044972471164077521701764250025016","247781346408541677846171493047610479641","107767679722784570175957813715600932047","55642571972255807596497010263897365339","126880499663240642544852739032872755595","166609694685271475250108918242895452082","125885496188533261250702341062059990770","95683369469834731550380057729041816455"],"threshold":0.9},"id":"CVE-2022-41958-8fd66aa7","signature_type":"Line"},{"target":{"file":"src/main/java/com/chaitin/xray/test/Main.java","function":"main"},"deprecated":false,"digest":{"function_hash":"324296726203122052026520003083791865398","length":165},"id":"CVE-2022-41958-f5083bbc","signature_type":"Function","signature_version":"v1","source":"https://github.com/4ra1n/super-xray/commit/4d0d59663596db03f39d7edd2be251d48b52dcfc"},{"signature_version":"v1","source":"https://github.com/4ra1n/super-xray/commit/4d0d59663596db03f39d7edd2be251d48b52dcfc","target":{"file":"src/main/java/com/chaitin/xray/form/LookupConfigForm.java","function":"LookupConfigForm"},"deprecated":false,"digest":{"function_hash":"59883116836499743035774035784656652169","length":1153},"id":"CVE-2022-41958-fe869b86","signature_type":"Function"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"}]}