GHSA-fh3m-562m-w4f6

Suggest an improvement
Source
https://github.com/advisories/GHSA-fh3m-562m-w4f6
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-fh3m-562m-w4f6/GHSA-fh3m-562m-w4f6.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-fh3m-562m-w4f6
Aliases
Published
2026-03-23T18:30:31Z
Modified
2026-03-26T21:11:24Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
DigitalOcean Droplet Agent: Command Injection via Metadata Service Endpoint
Details

A command injection vulnerability exists in DigitalOcean Droplet Agent through 1.3.2. The troubleshooting actioner component (internal/troubleshooting/actioner/actioner.go) processes metadata from the metadata service endpoint and executes commands specified in the TroubleshootingAgent.Requesting array without adequate input validation. While the code validates that artifacts exist in the validInvestigationArtifacts map, it fails to sanitize the actual command content after the "command:" prefix. This allows an attacker who can control metadata responses to inject and execute arbitrary OS commands with root privileges. The attack is triggered by sending a TCP packet with specific sequence numbers to the SSH port, which causes the agent to fetch metadata from http://169.254.169.254/metadata/v1.json.

The vulnerability affects the command execution flow in internal/troubleshooting/actioner/actioner.go (insufficient validation), internal/troubleshooting/command/exec.go (direct exec.CommandContext call), and internal/troubleshooting/command/command.go (command parsing without sanitization). This can lead to complete system compromise, data exfiltration, privilege escalation, and potential lateral movement across cloud infrastructure.

Database specific
{
    "cwe_ids": [
        "CWE-77"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-03-25T22:05:11Z",
    "nvd_published_at": "2026-03-23T17:16:37Z",
    "severity": "HIGH"
}
References

Affected packages

Go / github.com/digitalocean/droplet-agent

Package

Name
github.com/digitalocean/droplet-agent
View open source insights on deps.dev
Purl
pkg:golang/github.com/digitalocean/droplet-agent

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
0.0.0-20260107162243-1101ffcb5672

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-fh3m-562m-w4f6/GHSA-fh3m-562m-w4f6.json"