Lucene search

K
osvGoogleOSV:GO-2021-0068
HistoryApr 14, 2021 - 8:04 p.m.

Arbitrary code injection via the go command with cgo on Windows in cmd/go

2021-04-1420:04:52
Google
osv.dev
13

7.9 High

AI Score

Confidence

High

0.017 Low

EPSS

Percentile

88.0%

The go command may execute arbitrary code at build time when using cgo on Windows. This can be triggered by running go get on a malicious module, or any other time the code is built.