Chocolatey develops a package-management and automation ecosystem for Windows environments, spanning installer utilities, build-integration components, and command-line tools that simplify software deployment and configuration. Its vulnerability profile concentrates on permission and path-handling issues—specifically improper assignment of file-system permissions, exposure of resources across trust boundaries, and external control of file paths—which are characteristic of tools operating at system privilege levels during installation and provisioning workflows. Defenders should audit Chocolatey package sources and scripts for least-privilege execution and treat path-traversal and permission-escalation vectors as high-priority in environments where the tool manages critical infrastructure; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Chocolatey over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-15264HIGH The Boxstarter installer before version 2.13.0 configures C:\ProgramData\Boxstarter to be in the system-wide PATH environment variable. However, this directory is writable by norma | Oct 20, 2020 | 7.8 | 20 | NO | NO |
CVE-2022-45306MEDIUM Insecure permissions in Chocolatey Azure-Pipelines-Agent package v2.211.1 and below grants all users in the Authenticated Users group write privileges for the subfolder C:\agent an | Nov 29, 2022 | 4.3 | 18 | NO | NO |
CVE-2022-45305MEDIUM Insecure permissions in Chocolatey Python3 package v3.11.0 and below grants all users in the Authenticated Users group write privileges for the subfolder C:\Python311 and all files | Nov 29, 2022 | 4.3 | 18 | NO | NO |
CVE-2022-45304MEDIUM Insecure permissions in Chocolatey Cmder package v1.3.20 and below grants all users in the Authenticated Users group write privileges for the path C:\tools\Cmder and all files loca | Nov 29, 2022 | 4.3 | 18 | NO | NO |
CVE-2022-45301MEDIUM Insecure permissions in Chocolatey Ruby package v3.1.2.1 and below grants all users in the Authenticated Users group write privileges for the path C:\tools\ruby31 and all files loc | Nov 29, 2022 | 4.3 | 18 | NO | NO |
CVE-2022-45307MEDIUM Insecure permissions in Chocolatey PHP package v8.1.12 and below grants all users in the Authenticated Users group write privileges for the subfolder C:\tools\php81 and all files l | Nov 29, 2022 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Chocolatey.
Media articles that mention a CVE ID that affects a product developed by Chocolatey — matched by CVE ID, not by vendor name.