Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Chocolatey

First CVE: Oct 20, 2020Active for: 6 yearsTotal CVEs: 6

Chocolatey develops a package-management and automation ecosystem for Windows environments, spanning installer utilities, build-integration components, and command-line tools that simplify software deployment and configuration. Its vulnerability profile concentrates on permission and path-handling issues—specifically improper assignment of file-system permissions, exposure of resources across trust boundaries, and external control of file paths—which are characteristic of tools operating at system privilege levels during installation and provisioning workflows. Defenders should audit Chocolatey package sources and scripts for least-privilege execution and treat path-traversal and permission-escalation vectors as high-priority in environments where the tool manages critical infrastructure; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
6
Total CVEs
More Total CVEs than 86% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 5% of tracked vendors
4.9
Avg CVSS Score
Higher Avg CVSS Score than 10% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Chocolatey over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 20, 2020
5 years ago
Most Recent CVE
Nov 29, 2022
1,333 days ago

Products(6 total)

Top CVEs

Signals from CVEs in this vendor scope (6 CVEs).

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-15264HIGH
The Boxstarter installer before version 2.13.0 configures C:\ProgramData\Boxstarter to be in the system-wide PATH environment variable. However, this directory is writable by norma
Oct 20, 20207.820NONO
CVE-2022-45306MEDIUM
Insecure permissions in Chocolatey Azure-Pipelines-Agent package v2.211.1 and below grants all users in the Authenticated Users group write privileges for the subfolder C:\agent an
Nov 29, 20224.318NONO
CVE-2022-45305MEDIUM
Insecure permissions in Chocolatey Python3 package v3.11.0 and below grants all users in the Authenticated Users group write privileges for the subfolder C:\Python311 and all files
Nov 29, 20224.318NONO
CVE-2022-45304MEDIUM
Insecure permissions in Chocolatey Cmder package v1.3.20 and below grants all users in the Authenticated Users group write privileges for the path C:\tools\Cmder and all files loca
Nov 29, 20224.318NONO
CVE-2022-45301MEDIUM
Insecure permissions in Chocolatey Ruby package v3.1.2.1 and below grants all users in the Authenticated Users group write privileges for the path C:\tools\ruby31 and all files loc
Nov 29, 20224.318NONO
CVE-2022-45307MEDIUM
Insecure permissions in Chocolatey PHP package v8.1.12 and below grants all users in the Authenticated Users group write privileges for the subfolder C:\tools\php81 and all files l
Nov 29, 20224.314NONO
View all 6 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products6 CVEs
83%
17%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local1 (16.7%)
Network5 (83.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low6 (100.0%)
High0 (0.0%)
None0 (0.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (6 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Chocolatey.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Chocolatey — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Chocolatey's Products

View all 2 CNAs →

Top CWEs