{"id":"GO-2024-3344","summary":"Malicious plugin names, recipients, or identities causing arbitrary binary execution in filippo.io/age","details":"Malicious plugin names, recipients, or identities causing arbitrary binary execution in filippo.io/age","aliases":["GHSA-32gq-x56h-299c"],"modified":"2026-02-04T04:00:26.433286Z","published":"2024-12-20T20:36:46Z","related":["CGA-mf64-fv79-j395","CVE-2024-56327"],"database_specific":{"review_status":"REVIEWED","url":"https://pkg.go.dev/vuln/GO-2024-3344"},"references":[{"type":"ADVISORY","url":"https://github.com/FiloSottile/age/security/advisories/GHSA-32gq-x56h-299c"},{"type":"FIX","url":"https://github.com/FiloSottile/age/commit/482cf6fc9babd3ab06f6606762aac10447222201"}],"affected":[{"package":{"name":"filippo.io/age","ecosystem":"Go","purl":"pkg:golang/filippo.io/age"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.2.1"}]}],"ecosystem_specific":{"imports":[{"path":"filippo.io/age/plugin","symbols":["EncodeIdentity","EncodeRecipient","Identity.Unwrap","NewIdentity","NewIdentityWithoutData","NewRecipient","ParseIdentity","ParseRecipient","Recipient.Wrap","Recipient.WrapWithLabels","openClientConnection"]}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2024-3344.json"}}],"schema_version":"1.7.3","credits":[{"name":"⬡-49016"}]}