Tinygltf Project maintains a specialized glTF file-format parser library used for importing and processing 3D model data across graphics and visualization applications. The recurring vulnerability signal in this vendor centers on command and OS command injection weaknesses in how the library processes or handles input during file parsing. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tinygltf Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-3008HIGH The tinygltf library uses the C library function wordexp() to perform file path expansion on untrusted paths that are provided from the input file. This function allows for command | Sep 5, 2022 | 8.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tinygltf Project.
Media articles that mention a CVE ID that affects a product developed by Tinygltf Project — matched by CVE ID, not by vendor name.