Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wprm-fgrx-xj42

Опубликовано: 30 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 8.6

Описание

The go command may execute unexpected commands when operating in untrusted VCS repositories. This occurs when possibly dangerous VCS configuration is present in repositories. This can happen when a repository was fetched via one VCS (e.g. Git), but contains metadata for another VCS (e.g. Mercurial). Modules which are retrieved using the go command line, i.e. via "go get", are not affected.

The go command may execute unexpected commands when operating in untrusted VCS repositories. This occurs when possibly dangerous VCS configuration is present in repositories. This can happen when a repository was fetched via one VCS (e.g. Git), but contains metadata for another VCS (e.g. Mercurial). Modules which are retrieved using the go command line, i.e. via "go get", are not affected.

EPSS

Процентиль: 0%
0.00006
Низкий

8.6 High

CVSS3

Дефекты

CWE-73

Связанные уязвимости

CVSS3: 8.6
ubuntu
3 месяца назад

The go command may execute unexpected commands when operating in untrusted VCS repositories. This occurs when possibly dangerous VCS configuration is present in repositories. This can happen when a repository was fetched via one VCS (e.g. Git), but contains metadata for another VCS (e.g. Mercurial). Modules which are retrieved using the go command line, i.e. via "go get", are not affected.

CVSS3: 8.6
redhat
3 месяца назад

The go command may execute unexpected commands when operating in untrusted VCS repositories. This occurs when possibly dangerous VCS configuration is present in repositories. This can happen when a repository was fetched via one VCS (e.g. Git), but contains metadata for another VCS (e.g. Mercurial). Modules which are retrieved using the go command line, i.e. via "go get", are not affected.

CVSS3: 8.6
nvd
3 месяца назад

The go command may execute unexpected commands when operating in untrusted VCS repositories. This occurs when possibly dangerous VCS configuration is present in repositories. This can happen when a repository was fetched via one VCS (e.g. Git), but contains metadata for another VCS (e.g. Mercurial). Modules which are retrieved using the go command line, i.e. via "go get", are not affected.

CVSS3: 8.6
msrc
2 месяца назад

Unexpected command execution in untrusted VCS repositories in cmd/go

CVSS3: 8.6
debian
3 месяца назад

The go command may execute unexpected commands when operating in untru ...

EPSS

Процентиль: 0%
0.00006
Низкий

8.6 High

CVSS3

Дефекты

CWE-73