CVE-2022-36038 - CVE House
Back to Database
Status published High CVE-2022-36038

CircuitVerse potential RCE vulnerability via Oj.load

Vulnerability Description

CircuitVerse is an open-source platform which allows users to construct digital logic circuits online. A remote code execution (RCE) vulnerability in CircuitVerse allows authenticated attackers to execute arbitrary code via specially crafted JSON payloads. This issue may lead to Remote Code Execution (RCE). A patch is available in commit number 7b3023a99499a7675f10f2c1d9effdf10c35fb6e. There are currently no known workarounds.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-36038

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

CircuitVerse

View all reports →

Affected Software

CircuitVerse
Vulnerable Versions:
< 7b3023a99499a7675f10f2c1d9effdf10c35fb6e

Timeline

Official Publish: September 6th, 2022
Last Modified: April 23rd, 2025
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)