CVE-2022-46908: Sqlite
High severity, CVSS 7.3. EPSS: 0.4% chance of exploitation in the next 30 days.
SQLite through 3.40.0, when relying on --safe for execution of an untrusted CLI script, does not properly implement the azProhibitedFunctions protection mechanism, and instead allows UDF functions such as WRITEFILE.
Affected products
- Sqlite Sqlite: from 3.37.0, before 3.40.1 (fixed in 3.40.1)
Published 2022-12-12. Last modified 2026-06-17.