CVE-2022-25926 is a high-severity command injection vulnerability affecting versions of the window-control package prior to 1.4.5, specifically within the sendKeys function due to insufficient input sanitization. This flaw allows a local, low-privileged attacker to execute arbitrary commands on the system, leading to high impacts on confidentiality, integrity, and availability. While no public exploit code, Metasploit modules, or Nuclei templates are currently available, and it is not listed in the KEV catalog, its CVSS score of 7.8 indicates significant potential risk. The vulnerability has garnered minimal community discussion or media coverage, which is typical for a large percentage of CVEs.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.4.5CPE matchmatch criteria | cpe:2.3:a:window-control_project:window-control:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.