CVE-2022-23812 describes malicious code embedded in versions 10.1.1 through 10.1.2 of the node-ipc package, which targets users in Russia or Belarus by overwriting their files with a heart emoji. This vulnerability carries a critical CVSS score of 9.8, indicating a severe impact with high confidentiality, integrity, and availability risks, and can be exploited remotely without authentication. While there are no known public exploits or Metasploit modules, the vulnerability has garnered significant community attention with 5 mentions and 4 media articles, highlighting its deliberate sabotage nature. The EPSS score of 0.17383 further suggests a higher-than-average likelihood of exploitation compared to other CVEs.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 10.1.1, < 10.1.3CPE matchmatch criteria | cpe:2.3:a:node-ipc_project:node-ipc:*:*:*:*:*:node.js:*:* | ||
>= 11.0.0CPE matchmatch criteria | cpe:2.3:a:node-ipc_project:node-ipc:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.