Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-22984

23
FAUCET Score

CVE-2022-22984 is a command injection vulnerability affecting various Snyk CLI packages and plugins, including snyk, snyk-mvn-plugin, and snyk-gradle-plugin, among others. It allows attackers to execute arbitrary commands on the host system by providing crafted command-line flags when a user runs the 'snyk test' command on untrusted files. Rated as Medium severity (CVSS 6.3), this vulnerability has a low attack complexity and can lead to limited confidentiality, integrity, and availability impacts, particularly in CI/CD pipelines where arguments to the Snyk CLI can be controlled. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.1064.0CPE matchmatch criteria
cpe:2.3:a:snyk:snyk_cli:*:*:*:*:*:*:*:*
< 2.5.3CPE matchmatch criteria
cpe:2.3:a:snyk:snyk_cocoapods_cli:*:*:*:*:*:snyk:*:*
< 5.6.5CPE matchmatch criteria
cpe:2.3:a:snyk:snyk_docker_cli:*:*:*:*:*:snyk:*:*
< 3.24.5CPE matchmatch criteria
cpe:2.3:a:snyk:snyk_gradle_cli:*:*:*:*:*:snyk:*:*
< 1.1.6CPE matchmatch criteria
cpe:2.3:a:snyk:snyk_hex_cli:*:*:*:*:*:snyk:*:*

CVSS Data

CVSS version used by this source: 3.1

5.0MEDIUM

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
LOW
Exploitability Score
1.6
Impact Score
3.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
3.01%
Probability of exploitation in next 30 days
EPSS Percentile
86.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0301 is in the 95th percentile among its peer group of 21,954 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (11)

github_advisorypatch availablevia nvd_reference
View patch
npmpatch availablevia ghsa
Product: snyk-mvn-pluginFixed in: 2.31.3
npmpatch availablevia ghsa
Product: snyk-sbt-pluginFixed in: 2.16.2
npmpatch availablevia ghsa
Product: snyk-python-pluginFixed in: 1.24.2
npmpatch availablevia ghsa
Product: @snyk/snyk-hex-pluginFixed in: 1.1.6
npmpatch availablevia ghsa
Product: snyk-gradle-pluginFixed in: 3.24.5
npmpatch availablevia ghsa
Product: snyk-docker-pluginFixed in: 5.6.5
npmpatch availablevia ghsa
Product: @snyk/snyk-cocoapods-pluginFixed in: 2.5.3
npmpatch availablevia ghsa
Product: snykFixed in: 1.1064.0
redhatend of lifevia redhat_api
Product: OpenShift Service Mesh 2Fixed in: openshift-service-mesh/kiali-rhel8
redhatend of lifevia redhat_api
Product: OpenShift Service Mesh 2.1Fixed in: openshift-service-mesh/kiali-rhel8

Vendor Advisories (2)

npmGHSA-4x6g-3cmx-w76rmedium

Snyk plugins vulnerable to Command Injection

Nov 30, 2022
redhatCVE-2022-22984Moderate

snyk: snyk-hex-plugin: command injection

Nov 30, 2022

References

github.com / snyk/cli/commit/80d97a93326406e09776156daf72e3caa03ae25a
PatchThird Party Advisory
github.com / snyk/snyk-cocoapods-plugin/commit/c73e049c5200772babde61c40aab57296bf91381
PatchThird Party Advisory
github.com / snyk/snyk-docker-plugin/commit/d730d7630691a61587b120bb11daaaf4b58a8357
PatchThird Party Advisory
github.com / snyk/snyk-gradle-plugin/commit/bb1c1c72a75e97723a76b14d2d73f70744ed5009
PatchThird Party Advisory
github.com / snyk/snyk-hex-plugin/commit/e8dd2a330b40d7fc0ab47e34413e80a0146d7ac3
PatchThird Party Advisory
github.com / snyk/snyk-mvn-plugin/commit/02cda9ba1ea36b00ead3f6ec2de0f97397ebec50
PatchThird Party Advisory
github.com / snyk/snyk-python-plugin/commit/8591abdd9236108ac3e30c70c09238d6bb6aabf4
PatchThird Party Advisory
github.com / snyk/snyk-sbt-plugin/commit/99c09eb12c9f8f2b237aea9627aab1ae3cab6437
PatchThird Party Advisory
security.snyk.io / vuln/SNYK-JS-SNYK-3038622
ExploitPatchVendor Advisory
security.snyk.io / vuln/SNYK-JS-SNYKDOCKERPLUGIN-3039679
ExploitPatchVendor Advisory
security.snyk.io / vuln/SNYK-JS-SNYKGRADLEPLUGIN-3038624
ExploitPatchVendor Advisory
security.snyk.io / vuln/SNYK-JS-SNYKMVNPLUGIN-3038623
ExploitPatchVendor Advisory
security.snyk.io / vuln/SNYK-JS-SNYKPYTHONPLUGIN-3039677
ExploitPatchVendor Advisory
security.snyk.io / vuln/SNYK-JS-SNYKSBTPLUGIN-3038626
ExploitPatchVendor Advisory
security.snyk.io / vuln/SNYK-JS-SNYKSNYKCOCOAPODSPLUGIN-3038625
ExploitPatchVendor Advisory
security.snyk.io / vuln/SNYK-JS-SNYKSNYKHEXPLUGIN-3039680
ExploitPatchVendor Advisory
imperva.com / blog/how-scanning-your-projects-for-security-issues-can-lead-to-remote-code-execution
ExploitThird Party Advisory