Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-40764

26
FAUCET Score

CVE-2022-40764 is a critical arbitrary command execution vulnerability affecting Snyk CLI versions prior to 1.996.0, impacting Snyk IDE plugins and the snyk npm package. This flaw, demonstrated by shell metacharacters in a vendor.json ignore field, could allow an attacker to execute arbitrary commands, for instance, when a user views untrusted files in an IDE like Visual Studio Code. With a CVSS score of 7.8 (High), it presents a significant risk due to its low attack complexity and high impact on confidentiality, integrity, and availability. While there is no evidence of active exploitation, public exploit code, or significant community discussion, organizations using affected Snyk products should prioritize patching to mitigate this severe vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.996.0CPE matchmatch criteria
cpe:2.3:a:snyk:cli:*:*:*:*:*:*:*:*
< 1.19.1CPE matchmatch criteria
cpe:2.3:a:snyk:golang_cli:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.55%
Probability of exploitation in next 30 days
EPSS Percentile
42.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0055 is in the 82nd percentile among its peer group of 16,994 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

github_advisorypatch availablevia nvd_reference
View patch
npmpatch availablevia ghsa
Product: snykFixed in: 1.996.0
npmpatch availablevia ghsa
Product: snyk-go-pluginFixed in: 1.19.1
redhatend of lifevia redhat_api
Product: OpenShift Service Mesh 2Fixed in: openshift-service-mesh/kiali-rhel8
redhatend of lifevia redhat_api
Product: OpenShift Service Mesh 2.0Fixed in: openshift-service-mesh/kiali-rhel8
redhatend of lifevia redhat_api
Product: OpenShift Service Mesh 2.1Fixed in: openshift-service-mesh/kiali-rhel8

Vendor Advisories (2)

npmGHSA-hpqj-7cj6-hfj8high

Snyk CLI affected by Command Injection vulnerability

Oct 4, 2022
redhatCVE-2022-40764Moderate

snyk: Command Injection vulnerability affecting Snyk CLI

Oct 3, 2022

References

github.com / snyk/cli/releases/tag/v1.996.0
PatchRelease NotesThird Party Advisory
github.com / snyk/snyk-go-plugin/releases/tag/v1.19.1
PatchRelease NotesThird Party Advisory
support.snyk.io / hc/en-us/articles/7015908293789-CVE-2022-40764-Command-Injection-vulnerability-affecting-Snyk-CLI-versions-prior-to-1-996-0
PatchVendor Advisory
imperva.com / blog/how-scanning-your-projects-for-security-issues-can-lead-to-remote-code-execution
ExploitTechnical DescriptionThird Party Advisory