GHSA-qwqv-j7jr-4hp6 · Severity: critical · Ecosystem: pip — Argument injection in python-libnmap
In the python-libnmap package through 0.7.2 for Python, remote command execution can occur (if used in a client application that does not validate arguments). NOTE: the vendor believes it would be unrealistic for an application to call NmapProcess with arguments taken from input data that arrived over an untrusted network, and thus the CVSS score corresponds to an unrealistic use case. None of the NmapProcess documentation implies that this is an expected use case
Conclusion & alert: CVE-2022-30284 is rated High Exploit Risk (86.5/100): CVSS Critical severity, with high exploitation likelihood (EPSS 14.21%, 94th percentile). Core evidence: 2 public exploit reference(s) are indexed (Exploit-DB). EPSS rose +2.50% over the last day, indicating growing attacker interest. Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ | |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-04-02 | 11.71% | 14.21% | +2.50% |
| 2 | 2026-03-17 | 15.41% | 11.71% | -3.70% |
| 3 | 2026-01-02 | — | 15.41% | — |
Full EPSS history (35 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.0 | 3.1 | CRITICAL |
|
2.2 | 6.0 | [email protected] |
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
| 7.5 | 2.0 | HIGH |
|
10.0 | 6.4 | [email protected] |
GHSA-qwqv-j7jr-4hp6 · Severity: critical · Ecosystem: pip — Argument injection in python-libnmap
| vendor | priority | summary | link |
|---|---|---|---|
ubuntu
|
medium | CVE-2022-30284 medium priority: Ubuntu including 1 source packages (python-libnmap), 8 status rows across 8 suites (focal, impish, jammy, kinetic, lunar, mantic, noble, upstream): ignored 4, not-affected 3, needs-triage 1. | https://ubuntu.com/security/CVE-2022-30284 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| python-libnmap_project | python-libnmap | <= 0.7.2 | cpe:2.3:a:python-libnmap_project:python-libnmap:*:*:*:*:*:python:*:* |
| URL | Tags |
|---|---|
| https://github.com/savon-noir/python-libnmap/releases | Release Notes Third Party Advisory |
| https://libnmap.readthedocs.io/en/latest/process.html#using-libnmap-process | Exploit Third Party Advisory |
| https://pypi.org/project/python-libnmap/ | Product Third Party Advisory |
| https://www.swascan.com/security-advisory-libnmap-2/ | Exploit Mitigation Third Party Advisory |