GHSA-2v97-2cxm-mvp4
GitHub Security Advisory
⚠ Unreviewed
HIGH
Has CVE
Advisory Details
Code injection in Cmd.Start in os/exec before Go 1.17.11 and Go 1.18.3 allows execution of any binaries in the working directory named either "..com" or "..exe" by calling Cmd.Run, Cmd.Start, Cmd.Output, or Cmd.CombinedOutput when Cmd.Path is unset.
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: July 18, 2025 6:27 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.