FlawAtlas
Search the atlas
CVE-2024-28892 Critical

GoCast OS Command Injection vulnerability in github.com/mayuresh82/gocast

GoCast OS Command Injection vulnerability in github.com/mayuresh82/gocast

Exploit probability 6.4%
Published January 7, 2025
Required by Not available
Last source change March 3, 2026

02 / AFFECTED SOFTWARE

Affected packages

Go github.com/mayuresh82/gocast
Go github.com/mayuresh82/gocast

04 / EVIDENCE

Source records

Open Source Vulnerabilities GO-2024-3359

GoCast OS Command Injection vulnerability in github.com/mayuresh82/gocast

View original source
Open Source Vulnerabilities GHSA-5qww-56gc-f66c

An OS command injection vulnerability exists in the name parameter of GoCast 1.1.3. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.

View original source

05 / REFERENCES

Further evidence