CyberRota Analysis
AI-GeneratedThe vulnerability allows a malicious txtar to escape its execution context, enabling arbitrary writes to the trusted filesystem of the playground host. Additionally, a misconfigured invocation of the go vet command could permit remote code execution through a specially crafted environment configuration file. Organizations using independent deployments of golang.org/x/playground should prioritize addressing this issue to mitigate potential security risks.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A malicious txtar could escape the intended execution context and force arbitrary writes to the playground host's trusted filesystem. Disjointly, one of the three possible paths to invoke go vet on the playground host did not correctly restrict the execution environment. This permitted a Go process to make a read for an environment configuration file rooted in the playground host's $HOME. Together, a well-crafted go env file and the go vet invocation could lead to remote code execution in the playground host itself. This does not affect users of go.dev/play directly; however, it may affect independent deployments of golang.org/x/playground.