Malicious plugin names, recipients, or identities causing arbitrary binary execution in filippo.io/age
{ "review_status": "REVIEWED", "url": "https://pkg.go.dev/vuln/GO-2024-3344" }
{ "imports": [ { "path": "filippo.io/age/plugin", "symbols": [ "EncodeIdentity", "EncodeRecipient", "Identity.Unwrap", "NewIdentity", "NewIdentityWithoutData", "NewRecipient", "ParseIdentity", "ParseRecipient", "Recipient.Wrap", "Recipient.WrapWithLabels", "openClientConnection" ] } ] }