# CVE-2022-1365

## Summary

- **CVE ID:** CVE-2022-1365
- **Severity:** HIGH
- **CVSS Score:** 8.8 (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** CWE-359
- **Published:** Apr 15, 2022
- **Last Modified:** Mar 13, 2026

## Description

Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository lquixada/cross-fetch prior to 3.1.5.

## Affected Products

- lquixada — lquixada/cross-fetch (unspecified)

## References

- [CNA](https://huntr.dev/bounties/ab55dfdd-2a60-437a-a832-e3efe3d264ac)
- [CNA](https://github.com/lquixada/cross-fetch/commit/a3b3a9481091ddd06b8f83784ba9c4e034dc912a)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.27%
- **EPSS Percentile:** 50.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._