{"api_version":"1","generated_at":"2026-07-23T12:29:52+00:00","cve":"CVE-2022-20001","urls":{"html":"https://cve.report/CVE-2022-20001","api":"https://cve.report/api/cve/CVE-2022-20001.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2022-20001","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2022-20001"},"summary":{"title":"CVE-2022-20001","description":"fish is a command line shell. fish version 3.1.0 through version 3.3.1 is vulnerable to arbitrary code execution. git repositories can contain per-repository configuration that change the behavior of git, including running arbitrary commands. When using the default configuration of fish, changing to a directory automatically runs `git` commands in order to display information about the current repository in the prompt. If an attacker can convince a user to change their current directory into one controlled by the attacker, such as on a shared file system or extracted archive, fish will run arbitrary commands under the attacker's control. This problem has been fixed in fish 3.4.0. Note that running git in these directories, including using the git tab completion, remains a potential trigger for this issue. As a workaround, remove the `fish_git_prompt` function from the prompt.","state":"PUBLIC","assigner":"security-advisories@github.com","published_at":"2022-03-14 19:15:00","updated_at":"2023-11-07 03:42:00"},"problem_types":["CWE-74"],"metrics":[],"references":[{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BPZ7JV22DSZB5LNUCUEJ2HO3PKM2TVVK/","name":"FEDORA-2022-cd2c5e0634","refsource":"","tags":[],"title":"[SECURITY] Fedora 35 Update: fish-3.4.1-1.fc35 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/fish-shell/fish-shell/pull/8589","name":"https://github.com/fish-shell/fish-shell/pull/8589","refsource":"MISC","tags":[],"title":"fish_git_prompt: be careful about git config by ridiculousfish · Pull Request #8589 · fish-shell/fish-shell · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/fish-shell/fish-shell/security/advisories/GHSA-pj5f-6vxj-f5mq","name":"https://github.com/fish-shell/fish-shell/security/advisories/GHSA-pj5f-6vxj-f5mq","refsource":"CONFIRM","tags":[],"title":"Navigating to a compromised git repository may lead to arbitrary code exection · Advisory · fish-shell/fish-shell · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.debian.org/security/2022/dsa-5234","name":"DSA-5234","refsource":"DEBIAN","tags":[],"title":"Debian -- Security Information -- DSA-5234-1 fish","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BPZ7JV22DSZB5LNUCUEJ2HO3PKM2TVVK/","name":"FEDORA-2022-cd2c5e0634","refsource":"FEDORA","tags":[],"title":"[SECURITY] Fedora 35 Update: fish-3.4.1-1.fc35 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TRNMYS2LKB6TKOOBQQRSRQICDMWLZ4QL/","name":"FEDORA-2022-443c5ec2dd","refsource":"","tags":[],"title":"[SECURITY] Fedora 36 Update: fish-3.4.1-1.fc36 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://security.gentoo.org/glsa/202309-10","name":"GLSA-202309-10","refsource":"GENTOO","tags":[],"title":"Fish: User-assisted execution of arbitrary code (GLSA 202309-10) — Gentoo security","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TRNMYS2LKB6TKOOBQQRSRQICDMWLZ4QL/","name":"FEDORA-2022-443c5ec2dd","refsource":"FEDORA","tags":[],"title":"[SECURITY] Fedora 36 Update: fish-3.4.1-1.fc36 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/fish-shell/fish-shell/releases/tag/3.4.0","name":"https://github.com/fish-shell/fish-shell/releases/tag/3.4.0","refsource":"MISC","tags":[],"title":"Release fish 3.4.0 (released March 12, 2022)   · fish-shell/fish-shell · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2022-20001","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2022-20001","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2022","cve_id":"20001","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"debian","cpe5":"debian_linux","cpe6":"11.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2022","cve_id":"20001","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fedoraproject","cpe5":"fedora","cpe6":"35","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2022","cve_id":"20001","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fedoraproject","cpe5":"fedora","cpe6":"36","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2022","cve_id":"20001","vulnerable":"1","versionEndIncluding":"3.3.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"fishshell","cpe5":"fish","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2022-20001","qid":"181067","title":"Debian Security Update for fish (DSA 5234-1)"},{"cve":"CVE-2022-20001","qid":"182002","title":"Debian Security Update for fish (CVE-2022-20001)"},{"cve":"CVE-2022-20001","qid":"282555","title":"Fedora Security Update for fish (FEDORA-2022-cd2c5e0634)"},{"cve":"CVE-2022-20001","qid":"354349","title":"Amazon Linux Security Advisory for fish : ALAS2022-2022-056"},{"cve":"CVE-2022-20001","qid":"502216","title":"Alpine Linux Security Update for fish"},{"cve":"CVE-2022-20001","qid":"503923","title":"Alpine Linux Security Update for fish"},{"cve":"CVE-2022-20001","qid":"691033","title":"Free Berkeley Software Distribution (FreeBSD) Security Update for shells/fish (a3b10c9b-99d9-11ed-aa55-d05099fed512)"},{"cve":"CVE-2022-20001","qid":"710755","title":"Gentoo Linux Fish User-assisted execution of arbitrary code Vulnerability (GLSA 202309-10)"},{"cve":"CVE-2022-20001","qid":"901092","title":"Common Base Linux Mariner (CBL-Mariner) Security Update for fish (9070)"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"security-advisories@github.com","ID":"CVE-2022-20001","STATE":"PUBLIC","TITLE":"Injection in fish"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"fish-shell","version":{"version_data":[{"version_value":">= 3.1.0, < 3.4.0"}]}}]},"vendor_name":"fish-shell"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"fish is a command line shell. fish version 3.1.0 through version 3.3.1 is vulnerable to arbitrary code execution. git repositories can contain per-repository configuration that change the behavior of git, including running arbitrary commands. When using the default configuration of fish, changing to a directory automatically runs `git` commands in order to display information about the current repository in the prompt. If an attacker can convince a user to change their current directory into one controlled by the attacker, such as on a shared file system or extracted archive, fish will run arbitrary commands under the attacker's control. This problem has been fixed in fish 3.4.0. Note that running git in these directories, including using the git tab completion, remains a potential trigger for this issue. As a workaround, remove the `fish_git_prompt` function from the prompt."}]},"impact":{"cvss":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')"}]}]},"references":{"reference_data":[{"name":"https://github.com/fish-shell/fish-shell/security/advisories/GHSA-pj5f-6vxj-f5mq","refsource":"CONFIRM","url":"https://github.com/fish-shell/fish-shell/security/advisories/GHSA-pj5f-6vxj-f5mq"},{"name":"https://github.com/fish-shell/fish-shell/pull/8589","refsource":"MISC","url":"https://github.com/fish-shell/fish-shell/pull/8589"},{"name":"https://github.com/fish-shell/fish-shell/releases/tag/3.4.0","refsource":"MISC","url":"https://github.com/fish-shell/fish-shell/releases/tag/3.4.0"},{"refsource":"FEDORA","name":"FEDORA-2022-443c5ec2dd","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TRNMYS2LKB6TKOOBQQRSRQICDMWLZ4QL/"},{"refsource":"FEDORA","name":"FEDORA-2022-cd2c5e0634","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BPZ7JV22DSZB5LNUCUEJ2HO3PKM2TVVK/"},{"refsource":"DEBIAN","name":"DSA-5234","url":"https://www.debian.org/security/2022/dsa-5234"},{"refsource":"GENTOO","name":"GLSA-202309-10","url":"https://security.gentoo.org/glsa/202309-10"}]},"source":{"advisory":"GHSA-pj5f-6vxj-f5mq","discovery":"UNKNOWN"}},"nvd":{"publishedDate":"2022-03-14 19:15:00","lastModifiedDate":"2023-11-07 03:42:00","problem_types":["CWE-74"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":6.8},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:fishshell:fish:*:*:*:*:*:*:*:*","versionStartIncluding":"3.1.0","versionEndIncluding":"3.3.1","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2022","CveId":"20001","Ordinal":"209793","Title":"CVE-2022-20001","CVE":"CVE-2022-20001","Year":"2022"},"notes":[{"CveYear":"2022","CveId":"20001","Ordinal":"1","NoteData":"** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.","Type":"Description","Title":null}]}}}