CVE-2022-46908: Sqlite

High severity, CVSS 7.3. EPSS: 0.4% chance of exploitation in the next 30 days.

SQLite through 3.40.0, when relying on --safe for execution of an untrusted CLI script, does not properly implement the azProhibitedFunctions protection mechanism, and instead allows UDF functions such as WRITEFILE.

Affected products

  • Sqlite Sqlite: from 3.37.0, before 3.40.1 (fixed in 3.40.1)

Published 2022-12-12. Last modified 2026-06-17.