Intel

AIKIDO-2026-10635

github.com/aixgo-dev/aixgo is vulnerable to Command Injection

Command Injection Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Apr 29, 2026

75

High Risk

This Affects:

GOgithub.com/aixgo-dev/aixgo
0.3.0 - 0.7.2
Fixed in 0.7.3
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to command/argument injection due to the use of direct string construction to invoke external commands (such as gcloud) without validating or safely handling the arguments. This flaw could allow attackers to inject malicious command-line input, leading to unauthorized command execution or privilege escalation (gosec G204 context).

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

github.com/aixgo-dev/aixgo is vulnerable to Command Injection in versions 0.3.0 - 0.7.2.

How to fix this

Upgrade the github.com/aixgo-dev/aixgo library to the patch version.