Loading HuntDB...

GHSA-2hgx-m265-x6jf

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

IBM Robotic Process Automation with Automation Anywhere 10.0 could allow a remote attacker to execute arbitrary code on the system, caused by improper output encoding in an CSV export. By persuading a victim to download the CSV export, to open it in Microsoft Excel and to confirm the two security questions, an attacker could exploit this vulnerability to run any command or program on the victim's machine. IBM X-Force ID: 142651.

Related CVEs

Key Information

GHSA ID
GHSA-2hgx-m265-x6jf
Published
May 13, 2022 1:33 AM
Last Modified
May 13, 2022 1:33 AM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 2, 2025 6:26 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.