Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:40113
HistoryApr 11, 2023 - 11:30 p.m.

Arbitrary Code Execution

2023-04-1123:30:32
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
15
github
golang
arbitrary code execution
vulnerability
javascript
templates
sanitization
backticks.

0.003 Low

EPSS

Percentile

71.6%

github.com/golang/go is vulnerable to Arbitrary Code Execution. JavaScript templates do not consider backticks as string delimiters and do not escape them properly, which allows an attacker to bypass sanitization and execute arbitrary code on the system.