VYPR
Unrated severityOSV Advisory· Published Jan 8, 2026· Updated Feb 26, 2026

Greenshot Vulnerable to OS Command Injection via ExternalCommand Plugin

CVE-2026-22035

Description

Greenshot is an open source Windows screenshot utility. Versions 1.3.310 and below arvulnerable to OS Command Injection through unsanitized filename processing. The FormatArguments method in ExternalCommandDestination.cs:269 uses string.Format() to insert user-controlled filenames directly into shell commands without sanitization, allowing attackers to execute arbitrary commands by crafting malicious filenames containing shell metacharacters. This issue is fixed in version 1.3.311.

Affected products

1
  • Range: Greenshot-RELEASE-1.2.8.12, Greenshot-RELEASE-1.2.8.14, bug/546-admin-install, …

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.