{"id":"CVE-2022-0624","aliases":["GHSA-3j8f-xvm3-ffx4"],"url":"https://o3.security/vulnerability/CVE-2022-0624","summary":"Authorization Bypass Through User-Controlled Key in ionicabizau/parse-path","details":"Authorization Bypass Through User-Controlled Key in GitHub repository ionicabizau/parse-path prior to 5.0.0.","published":"2022-06-28T09:10:10Z","modified":"2026-08-12T03:51:47.075888042Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"},"epss":{"score":0.0089,"percentile":0.56208,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"npm","name":"parse-path","fixedVersion":"5.0.0"}],"fix":{"url":"https://github.com/ionicabizau/parse-path/commit/f9ad8856a3c8ae18e1cf4caef5edbabbc42840e8","label":"ionicabizau/parse-path@f9ad885"},"references":[{"type":"WEB","url":"https://huntr.dev/bounties/afffb2bd-fb06-4144-829e-ecbbcbc85388"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/0xxx/CVE-2022-0624.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-0624"},{"type":"FIX","url":"https://github.com/ionicabizau/parse-path/commit/f9ad8856a3c8ae18e1cf4caef5edbabbc42840e8"},{"type":"PACKAGE","url":"https://github.com/ionicabizau/parse-path"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:47.075888042Z"}}