EchelonGraph verdictPlan mitigationSerious severity, but no confirmed exploitation yet.
- •High severity, but no confirmed exploitation yet
CISA-KEV: Not listedEPSS PROB: 0.4%CVSS: 8.8Exploit: None knownExposed services: Not assessed
No fix is confirmed yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for the fix.
A malicious txtar could escape the intended execution context and force arbitrary writes to the playground host's trusted filesystem.
Disjointly, one of the three possible paths to invoke go vet on the playground host did not correctly restrict the execution environment. This permitted a Go process to make a read for an environment configuration file rooted in the playground host's $HOME.
Together, a well-crafted go env file and the go vet invocation could lead to remote code execution in the playground host itself.
This does not affect users of go.dev/play directly; however, it may affect independent deployments of golang.org/x/playground.
CISA SSVCTrack at low or medium mission impact; Track* at high (mission-essential systems).
No fix is confirmed yet. Restrict network exposure of the affected system or apply the vendor's mitigation within your standard update timelines, and watch the vendor's advisory for the fix.
Exploitation none (CISA Vulnrichment) · Automatable no (CISA Vulnrichment) · Technical impact total (CISA Vulnrichment). Mission impact is CISA's Mission & Well-being decision point, and only you can judge it: high means the affected system is essential to your organisation's mission, or its compromise could cause irreversible harm to people. CISA's decision table