Downloading and building modules with malicious version strings can cause local code execution. On systems with Mercurial (hg) installed, downloading modules from non-standard sources (e.g., custom domains) can cause unexpected code execution due to how external VCS commands are constructed. This issue can also be triggered by providing a malicious version string to the toolchain. On systems with Git installed, downloading and building modules with malicious version strings can allow an attacker to write to arbitrary files on the filesystem. This can only be triggered by explicitly providing the malicious version strings to the toolchain and does not affect usage of @latest or bare module paths.
CVSS Details
- CVSS 3.1 Base Score: 7
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade go | Jan 29, 2026 | Jan 28, 2026 |
| Amazon Linux Ami 2 | — | Upgrade golang-docsUpgrade golang-testsUpgrade golang-sharedUpgrade golang-binUpgrade amazon-ssm-agentUpgrade golangUpgrade golang-miscUpgrade golang-src | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade golistUpgrade oci-add-hooks-debuginfoUpgrade runfinch-finchUpgrade nerdctlUpgrade amazon-ecr-credential-helperUpgrade libcap-debugsourceUpgrade cni-plugins-debuginfoUpgrade containerd-stressUpgrade cni-pluginsUpgrade golang-sharedUpgrade oci-add-hooksUpgrade cni-plugins-debugsourceUpgrade libcap-debuginfoUpgrade golist-debuginfoUpgrade captree-debuginfoUpgrade golang-docsUpgrade amazon-cloudwatch-agentUpgrade amazon-ssm-agentUpgrade containerd-stress-debuginfoUpgrade oci-add-hooks-debugsourceUpgrade golist-debugsourceUpgrade captreeUpgrade containerd-debuginfoUpgrade containerdUpgrade containerd-debugsourceUpgrade golang-srcUpgrade golang-binUpgrade golang-miscUpgrade libcap-staticUpgrade soci-snapshotterUpgrade golang-testsUpgrade golangUpgrade libcapUpgrade libcap-devel | Feb 10, 2026 | Jan 28, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Jan 28, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | Jan 28, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub