CVE-2022-29351
Critical · CVSS 9.8TiddlyWiki5 — Arbitrary File Upload leading to Code Execution (SVG)
- CVSS
- 9.8
- nvd
- EPSS
- 2.41%
- 82th pct
- KEV
- No
- Class
- oss containerizable
- CWE-434
Description
An arbitrary file upload vulnerability in the file upload module of Tiddlywiki5 v5.2.2 allows attackers to execute arbitrary code via a crafted SVG file. Note: The vendor argues that this is not a legitimate issue and there is no vulnerability here.
Search profile — drives PoC discovery
Symbols file upload modulecrafted SVG filecorruptsvgfileTiddlyWiki5 uploadSVG XSStiddler import
Keywords CVE-2022-29351TiddlyWiki5arbitrary file uploadSVG file uploadCWE-434tiddlywiki SVG exploittiddlywiki file upload vulnerabilitycorruptsvgfiletiddlywiki RCEtiddlywiki5 v5.2.2
Versions: v5.2.2
References
Status: enriched · ingested 2026-07-05T18:00:39.000Z · profiled 2026-07-05T18:30:39.000Z