Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:40160
HistoryApr 18, 2023 - 12:46 p.m.

Arbitrary Code Execution

2023-04-1812:46:23
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
18
github
golang
vulnerable
javascript
templates
sanitization
code execution
system

0.003 Low

EPSS

Percentile

71.6%

github.com/golang/go is vulnerable to Arbitrary Code Execution. JavaScript templates do not consider backticks as string delimiters and do not escape them properly, which allows an attacker to bypass sanitization and execute arbitrary code on the system.