Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-46165

19
FAUCET Score

CVE-2022-46165 is a stored cross-site scripting (XSS) vulnerability affecting Syncthing versions prior to 1.23.5. A compromised Syncthing instance could sync malicious files with embedded HTML/JavaScript in their names, or an attacker could add a device with a malicious name. If a user hovers over these elements in the web UI, the script could execute, potentially altering settings or adding devices. Rated as Medium severity (CVSS 5.4), this vulnerability requires user interaction (UI:R) and authenticated access (PR:L) to exploit, but can lead to changes in shared folder settings or device additions (I:L) and information disclosure (C:L). The attack vector is network-based (AV:N) with low attack complexity (AC:L). There is currently no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, indicating a low level of public attention.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.23.5CPE matchmatch criteria
cpe:2.3:a:syncthing:syncthing:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

4.6MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
2.1
Impact Score
2.5
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.78%
Probability of exploitation in next 30 days
EPSS Percentile
52.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0078 is in the 87th percentile among its peer group of 15,225 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
gopatch availablevia ghsa
Product: github.com/syncthing/syncthingFixed in: 1.23.5

Vendor Advisories (1)

goGHSA-9rp6-23gf-4c3hmedium

syncthing vulnerable to Cross-site Scripting (XSS) in Web GUI

Jun 6, 2023

References

github.com / syncthing/syncthing/commit/73c52eafb6566435dffd979c3c49562b6d5a4238
Patch
github.com / syncthing/syncthing/security/advisories/GHSA-9rp6-23gf-4c3h
ExploitVendor Advisory
lists.fedoraproject.org / archives/list/[email protected]/message/IRYGBFJPVBW6PPTETNIBWQJE4HJSA5PJ
lists.fedoraproject.org / archives/list/[email protected]/message/XEBWSQVGHSTR4ZO7LVVEMPEGMV2DS5XR