{"id":"GHSA-jq43-q8mx-r7mq","summary":"SwiftTerm Code Injection vulnerability","details":"### Impact\n\nAttacker could modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.\n\n### Credit\nThese bugs were found and disclosed by David Leadbeater \u003cdgl@dgl.cx\u003e (@dgl at Github.com)\n\n### Patches\n\nFixed in version ce596e0dc8cdb288bc7ed5c6a59011ee3a8dc171\n\n### Workarounds\n\nThere are no workarounds available\n\n### References\n\nSimilar exploits to this existed in the past, for terminal emulators:\n\nhttps://nvd.nist.gov/vuln/detail/CVE-2003-0063\nhttps://nvd.nist.gov/vuln/detail/CVE-2008-2383\n\nAdditional background and information is also available:\n\nhttps://marc.info/?l=bugtraq&m=104612710031920&w=2\nhttps://bugs.debian.org/cgi-bin/bugreport.cgi?bug=510030\n","aliases":["CVE-2022-23465"],"modified":"2024-02-09T00:34:39Z","published":"2023-07-14T21:58:43Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2023-07-14T21:58:43Z","nvd_published_at":"2022-12-02T23:15:16Z","cwe_ids":["CWE-94"]},"references":[{"type":"WEB","url":"https://github.com/migueldeicaza/SwiftTerm/security/advisories/GHSA-jq43-q8mx-r7mq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-23465"},{"type":"WEB","url":"https://github.com/migueldeicaza/SwiftTerm/commit/a94e6b24d24ce9680ad79884992e1dff8e150a31"},{"type":"PACKAGE","url":"https://github.com/migueldeicaza/SwiftTerm"}],"affected":[{"package":{"name":"github.com/migueldeicaza/SwiftTerm","ecosystem":"SwiftURL","purl":"pkg:swift/github.com/migueldeicaza/SwiftTerm"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.2.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/07/GHSA-jq43-q8mx-r7mq/GHSA-jq43-q8mx-r7mq.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N"}]}