CVE-2026-22208 is a critical remote code execution vulnerability affecting OpenS100, the reference S-100 viewer, prior to commit 753cf29. It allows an attacker to execute arbitrary commands on a user's system by providing a malicious S-100 portrayal catalogue. The vulnerability stems from an unrestricted Lua interpreter that exposes sensitive system libraries. This vulnerability has a CVSS score of 9.6 (CRITICAL) due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability, requiring user interaction to trigger. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available, though it has garnered significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| OpenS100 Project | OpenS100 | >= 0, < 753cf294434e8d3961f20a567c4d99151e3b530dCNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.