Back to Database
Status published
Medium
CVE-2022-41945
Remote Code Execution (RCE) vulnerability in super-xray via URL input
Vulnerability Description
super-xray is a vulnerability scanner (xray) GUI launcher. In version 0.1-beta, the URL is not filtered and directly spliced into the command, resulting in a possible RCE vulnerability. Users should upgrade to super-xray 0.2-beta.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-41945
Credits & Attribution
No credits recorded in the NVD database.
References
Affected Vendor
4ra1n
View all reports →Affected Software
super-xray
Vulnerable Versions:
< 0.2-beta
Timeline
Official Publish:
November 21st, 2022
Last Modified:
April 22nd, 2025
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H