The P4 Project maintains Perforce, a version-control and collaboration platform widely used in software development and game development environments, with a narrowly scoped but strategically positioned product footprint. Its observed vulnerability pattern centers on OS command injection weaknesses, reflecting the risk surface inherent to a system that executes build, deployment, and integration workflows with access to underlying shell environments. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by P4 Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-25171CRITICAL The package p4 before 0.0.7 are vulnerable to Command Injection via the run() function due to improper input sanitization | Dec 20, 2022 | 9.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by P4 Project.
Media articles that mention a CVE ID that affects a product developed by P4 Project — matched by CVE ID, not by vendor name.