Intel

AIKIDO-2026-10634

github.com/aixgo-dev/aixgo is vulnerable to Log Injection

Log Injection Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Apr 29, 2026

25

Low Risk

This Affects:

GOgithub.com/aixgo-dev/aixgo
0.3.0 - 0.7.2
Fixed in 0.7.3
Are you affected? Scan for Free

TL;DR

Log statements embedded potentially attacker-influenced values (e.g., environment, region, project identifiers) directly into log lines, triggering gosec G706 risk of log forging/injection.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

github.com/aixgo-dev/aixgo is vulnerable to Log Injection in versions 0.3.0 - 0.7.2.

How to fix this

Upgrade the github.com/aixgo-dev/aixgo library to the patch version.