CVE-2018-7187: Debian Linux
High severity, CVSS 8.8. EPSS: 63% chance of exploitation in the next 30 days.
The "go get" implementation in Go 1.9.4, when the -insecure command-line option is used, does not validate the import path (get/vcs.go only checks for "://" anywhere in the string), which allows remote attackers to execute arbitrary OS commands via a crafted web site.
Affected products
- Debian Debian Linux: version 7.0 only; version 9.0 only
- Golang Go: before 1.9.5 (fixed in 1.9.5); from 1.10, before 1.10.1 (fixed in 1.10.1)
Published 2018-02-16. Last modified 2026-06-17.