Msys2 is a lightweight Unix-like environment and build toolchain for Windows that provides GNU utilities and a POSIX shell, serving developers and build systems that require cross-platform compatibility. Its vulnerability profile is correspondingly narrow, reflecting the focused scope of this development tool. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Msys2 over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-37172HIGH Incorrect access control in the install directory (C:\msys64) of Msys2 v20220603 and below allows authenticated attackers to execute arbitrary code via overwriting binaries located | Aug 30, 2022 | 7.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Msys2.
Media articles that mention a CVE ID that affects a product developed by Msys2 — matched by CVE ID, not by vendor name.