CVE-2018-16874: Input Validation
In Go before 1.10.6 and 1.11.x before 1.11.3, the "go get" command is vulnerable to directory traversal when executed with the import path of a malicious Go package which contains curly braces (both '{' and '}' characters). Specifically, it is only vulnerable in GOPATH mode, but not in module mode (the distinction is documented at https://golang.org/cmd/go/#hdr-Moduleawaregoget). The attacker can cause an arbitrary filesystem write, which can lead to code execution.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-16874?
CVE-2018-16874 is a vulnerability in Go before 1.10.6 and 1.11.x before 1.11.3 that allows directory traversal.
How does CVE-2018-16874 affect Go?
CVE-2018-16874 affects Go versions before 1.10.6 and 1.11.x before 1.11.3.
How severe is CVE-2018-16874?
CVE-2018-16874 has a severity rating of 8.1 (High).
Which software versions are affected by CVE-2018-16874?
CVE-2018-16874 affects Go before 1.10.6 and 1.11.x before 1.11.3.
How do I fix CVE-2018-16874?
To fix CVE-2018-16874, update to Go version 1.10.6 or higher for Go 1.10.x, and update to Go version 1.11.3 or higher for Go 1.11.x.