CVE Explorer
CVE-2026-22035
Greenshot is an open source Windows screenshot utility. Versions 1.3.310 and below arvulnerable to OS Command Injection through unsanitized filename processing. The FormatArguments method in ExternalCommandDestination.cs:269 uses string.Format() to insert user-controlled filenames directly into shell commands without sanitization, allowing attackers to execute arbitrary commands by crafting malicious filenames containing shell metacharacters. This issue is fixed in version 1.3.311.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"greenshot","vendor":"greenshot","versions":[{"status":"affected","version":"< 1.3.311"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:084c8c2d084c8827cf156d9b6649324f83441f36995563c41aceb460eebbf477 · sha256:ffa9db15fbc3f628… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:084c8c2d084c8827cf156d9b6649324f83441f36995563c41aceb460eebbf477 · sha256:ffa9db15fbc3f628… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-78","description":"CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:084c8c2d084c8827cf156d9b6649324f83441f36995563c41aceb460eebbf477 · sha256:ffa9db15fbc3f628… · /containers/cna/problemTypes/0/descriptions/0
Source references
4 source assertions{"name":"https://github.com/greenshot/greenshot/commit/5dedd5c9f0a9896fa0af1d4980d875a48bf432cb","tags":["x_refsource_MISC"],"url":"https://github.com/greenshot/greenshot/commit/5dedd5c9f0a9896fa0af1d4980d875a48bf432cb"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:084c8c2d084c8827cf156d9b6649324f83441f36995563c41aceb460eebbf477 · sha256:ffa9db15fbc3f628… · /containers/cna/references/1
{"name":"https://github.com/greenshot/greenshot/releases/tag/v1.3.311","tags":["x_refsource_MISC"],"url":"https://github.com/greenshot/greenshot/releases/tag/v1.3.311"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:084c8c2d084c8827cf156d9b6649324f83441f36995563c41aceb460eebbf477 · sha256:ffa9db15fbc3f628… · /containers/cna/references/2
{"name":"https://github.com/greenshot/greenshot/security/advisories/GHSA-7hvw-q8q5-gpmj","tags":["x_refsource_CONFIRM"],"url":"https://github.com/greenshot/greenshot/security/advisories/GHSA-7hvw-q8q5-gpmj"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:084c8c2d084c8827cf156d9b6649324f83441f36995563c41aceb460eebbf477 · sha256:ffa9db15fbc3f628… · /containers/cna/references/0
{"tags":["exploit"],"url":"https://github.com/greenshot/greenshot/security/advisories/GHSA-7hvw-q8q5-gpmj"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:084c8c2d084c8827cf156d9b6649324f83441f36995563c41aceb460eebbf477 · sha256:ffa9db15fbc3f628… · /containers/adp/0/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.