Critical severity9.8NVD Advisory· Published Jun 23, 2022· Updated Jun 17, 2026
CVE-2022-33127
CVE-2022-33127
Description
The function that calls the diff tool in Diffy 3.4.1 does not properly handle double quotes in a filename when run in a windows environment. This allows attackers to execute arbitrary commands via a crafted string.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
diffyRubyGems | < 3.4.1 | 3.4.1 |
Affected products
2- Diffy/Diffydescription
Patches
Vulnerability mechanics
References
5- github.com/samg/diffy/commit/478f392082b66d38f54a02b4bb9c41be32fd6593nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-5ww9-9qp2-x524ghsaADVISORY
- github.com/samg/diffy/blob/56fd935aea256742f7352b050592542d3d153bf6/CHANGELOGnvdRelease NotesThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-33127ghsaADVISORY
- github.com/rubysec/ruby-advisory-db/blob/master/gems/diffy/CVE-2022-33127.ymlghsaWEB
News mentions
0No linked articles in our index yet.