CVE-2024-28892
Critical
GoCast OS Command Injection vulnerability in github.com/mayuresh82/gocast
GoCast OS Command Injection vulnerability in github.com/mayuresh82/gocast
Exploit probability
6.4%
Published
January 7, 2025
Required by
Not available
Last source change
March 3, 2026
02 / AFFECTED SOFTWARE
Affected packages
04 / EVIDENCE
Source records
Open Source Vulnerabilities
GO-2024-3359
View original source
GoCast OS Command Injection vulnerability in github.com/mayuresh82/gocast
Open Source Vulnerabilities
GHSA-5qww-56gc-f66c
View original source
An OS command injection vulnerability exists in the name parameter of GoCast 1.1.3. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.
05 / REFERENCES