github.com/aixgo-dev/aixgo is vulnerable to Command Injection
75
High Risk
Affected versions of this package are vulnerable to command/argument injection due to the use of direct string construction to invoke external commands (such as gcloud) without validating or safely handling the arguments. This flaw could allow attackers to inject malicious command-line input, leading to unauthorized command execution or privilege escalation (gosec G204 context).
You are affected if you are using a version that falls within the vulnerable range.
github.com/aixgo-dev/aixgo is vulnerable to Command Injection in versions 0.3.0 - 0.7.2.
Upgrade the github.com/aixgo-dev/aixgo library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant