VYPR
Unrated severityNVD Advisory· Published Sep 8, 2023· Updated Feb 13, 2025

Arbitrary code execution via go.mod toolchain directive in cmd/go

CVE-2023-39320

Description

The go.mod toolchain directive, introduced in Go 1.21, can be leveraged to execute scripts and binaries relative to the root of the module when the "go" command was executed within the module. This applies to modules downloaded using the "go" command from the module proxy, as well as modules downloaded directly using VCS software.

Affected products

21

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

6

News mentions

0

No linked articles in our index yet.