VYPR
Critical severity9.8GHSA Advisory· Published May 7, 2024· Updated Jun 17, 2026

CVE-2024-33434

CVE-2024-33434

Description

An issue in tiagorlampert CHAOS v5.0.1 before 1b451cf62582295b7225caf5a7b506f0bad56f6b and 24c9e109b5be34df7b2bce8368eae669c481ed5e allows a remote attacker to execute arbitrary code via the unsafe concatenation of the filename argument into the buildStr string without any sanitization or filtering.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/tiagorlampert/CHAOSGo
< 0.0.0-20220716132853-b47438d36e3a0.0.0-20220716132853-b47438d36e3a

Affected products

2

Patches

Vulnerability mechanics

References

9

News mentions

0

No linked articles in our index yet.