CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2022-46640

Critical · CVSS 9.8

Nanoleaf Desktop App — Command Injection via crafted HTTP request

CVSS
9.8
nvd
EPSS
KEV
No
Class
other
CWE-77, CWE-77

Description

Nanoleaf Desktop App before v1.3.1 was discovered to contain a command injection vulnerability which is exploited via a crafted HTTP request.

Search profile — drives PoC discovery

Symbols HTTP request handlercommand injectionexecshellspawnchild_process
Keywords CVE-2022-46640Nanoleaf Desktop Appcommand injectionHTTP requestPoCexploitpwning.techv1.3.1
Versions: < v1.3.1

Ranked PoCs (1) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

References

Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T12:30:39.000Z