{"id":"CVE-2022-21187","aliases":["GHSA-mv2w-4jqc-6fg4","PYSEC-2022-163","PYSEC-2026-563","SNYK-PYTHON-LIBVCS-2421204"],"url":"https://o3.security/vulnerability/CVE-2022-21187","summary":"Command Injection","details":"The package libvcs before 0.11.1 are vulnerable to Command Injection via argument injection. When calling the update_repo function (when using hg), the url parameter is passed to the hg clone command. By injecting some hg options it was possible to get arbitrary command execution.","published":"2022-03-14T17:15:17.020Z","modified":"2026-08-12T03:51:15.895131481Z","cvss":{"score":8.1,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.03594,"percentile":0.88573,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"libvcs","fixedVersion":"0.11.1"},{"ecosystem":"PyPI","name":"vcspull","fixedVersion":"1.11.1"}],"fix":{"url":"https://github.com/vcs-python/libvcs/pull/306","label":"vcs-python/libvcs#306"},"references":[{"type":"WEB","url":"https://github.com/vcs-python/libvcs/blob/v0.11.1/CHANGES%23libvcs-0111-2022-03-12"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/21xxx/CVE-2022-21187.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-21187"},{"type":"ADVISORY","url":"https://snyk.io/vuln/SNYK-PYTHON-LIBVCS-2421204"},{"type":"FIX","url":"https://github.com/vcs-python/libvcs/pull/306"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:15.895131481Z"}}