{"id":"CVE-2022-4885","aliases":["GHSA-7jrw-p8jc-v6qw","PYSEC-2026-826"],"title":"sviehb/jefferson vulnerable to path traversal","summary":"sviehb/jefferson vulnerable to path traversal","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","vendor":"jefferson","product":"jefferson","ecosystem":"pip","affected":["jefferson < 0.4"],"patched":["jefferson 0.4"],"published":"2023-01-11","updated":"2026-07-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-7jrw-p8jc-v6qw","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2022-4885"},{"url":"https://github.com/sviehb/jefferson/pull/36"},{"url":"https://github.com/sviehb/jefferson/commit/53b3f2fc34af0bb32afbcee29d18213e61471d87"},{"url":"https://github.com/sviehb/jefferson"},{"url":"https://github.com/sviehb/jefferson/releases/tag/v0.4"},{"url":"https://vuldb.com/?ctiid.218020"},{"url":"https://vuldb.com/?id.218020"}],"tags":["osv","pip"],"epss":0.00746,"epssPercentile":0.52903,"ingestedAt":"2026-07-08T18:25:47.039Z","slug":"CVE-2022-4885","body":"## Overview\n\nA vulnerability has been found in the sviehb/jefferson JFFS2 filesystem extraction tool. This vulnerability affects unknown code of the file `src/scripts/jefferson`. The manipulation leads to path traversal. The attack can be initiated remotely. Upgrading to version 0.4 is able to address this issue as it includes https://github.com/sviehb/jefferson/commit/53b3f2fc34af0bb32afbcee29d18213e61471d87.\n\n## Affected packages\n\n- `jefferson < 0.4`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `jefferson 0.4`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}