Squirrel.Windows is a lightweight application-update framework for Windows desktop software, with vulnerabilities concentrated in the core library's installer and path-resolution logic. The recurring weakness class involves uncontrolled search-path elements, which reflects the inherent risk of file-system operations during application updates and installation. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Squirrel.Windows Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-46330HIGH Squirrel.Windows is both a toolset and a library that provides installation and update functionality for Windows desktop applications. Installers generated by Squirrel.Windows 2.0. | Dec 21, 2022 | 7.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Squirrel.Windows Project.
Media articles that mention a CVE ID that affects a product developed by Squirrel.Windows Project — matched by CVE ID, not by vendor name.