Security Advisory

CVE-2026-22035

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-01-08 00:10:28
Last updated 2026-02-26 15:04:55
Assigner GitHub_M
State PUBLISHED

Description

Greenshot is an open source Windows screenshot utility. Versions 1.3.310 and below arvulnerable to OS Command Injection through unsanitized filename processing. The FormatArguments method in ExternalCommandDestination.cs:269 uses string.Format() to insert user-controlled filenames directly into shell commands without sanitization, allowing attackers to execute arbitrary commands by crafting malicious filenames containing shell metacharacters. This issue is fixed in version 1.3.311.