Executive brief
This advisory has been withdrawn and is no longer considered valid. The original report claimed that TiddlyWiki5, a personal wiki and note-taking application, contained a vulnerability allowing attackers to upload malicious SVG files to execute arbitrary code. However, investigation determined the vulnerability claim was not accurate.
Technical details
The original advisory (CVE-2022-29351) described an arbitrary file upload vulnerability (CWE-434) in the file upload module of TiddlyWiki5 v5.2.2, claiming that specially crafted SVG files could lead to arbitrary code execution. The vulnerability was accessible over the network without authentication or user interaction. However, the advisory was withdrawn in May 2024 after it was determined that the vulnerability claim was not valid. No patch or mitigation is necessary as the underlying issue does not exist.
Affected products
- TiddlyWiki TiddlyWiki5 up to 5.2.2
Timeline
- 2022-05-17: disclosed
- 2024-05-17: other: Advisory withdrawn - determined to be invalid