CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2022-29351

Critical · CVSS 9.8

TiddlyWiki5 — Arbitrary File Upload leading to Code Execution (SVG)

CVSS
9.8
nvd
EPSS
2.41%
82th pct
KEV
No
Class
oss containerizable
CWE-434

Description

An arbitrary file upload vulnerability in the file upload module of Tiddlywiki5 v5.2.2 allows attackers to execute arbitrary code via a crafted SVG file. Note: The vendor argues that this is not a legitimate issue and there is no vulnerability here.

Search profile — drives PoC discovery

Symbols file upload modulecrafted SVG filecorruptsvgfileTiddlyWiki5 uploadSVG XSStiddler import
Keywords CVE-2022-29351TiddlyWiki5arbitrary file uploadSVG file uploadCWE-434tiddlywiki SVG exploittiddlywiki file upload vulnerabilitycorruptsvgfiletiddlywiki RCEtiddlywiki5 v5.2.2
Versions: v5.2.2

References

Status: enriched · ingested 2026-07-05T18:00:39.000Z · profiled 2026-07-05T18:30:39.000Z