{"id":"GHSA-32gq-x56h-299c","aliases":["GO-2024-3344"],"url":"https://o3.security/vulnerability/GHSA-32gq-x56h-299c","summary":"age vulnerable to malicious plugin names, recipients, or identities causing arbitrary binary execution","details":"A plugin name containing a path separator may allow an attacker to execute an arbitrary binary.\n\nSuch a plugin name can be provided to the age CLI through an attacker-controlled recipient or identity string, or to the [`plugin.NewIdentity`](https://pkg.go.dev/filippo.io/age/plugin#NewIdentity), [`plugin.NewIdentityWithoutData`](https://pkg.go.dev/filippo.io/age/plugin#NewIdentityWithoutData), or [`plugin.NewRecipient`](https://pkg.go.dev/filippo.io/age/plugin#NewRecipient) APIs.\n\nOn UNIX systems, a directory matching `${TMPDIR:-/tmp}/age-plugin-*` needs to exist for the attack to succeed.\n\nThe binary is executed with a single flag, either `--age-plugin=recipient-v1` or `--age-plugin=identity-v1`. The standard input includes the recipient or identity string, and the random file key (if encrypting) or the header of the file (if decrypting). The format is constrained by the [age-plugin](https://c2sp.org/age-plugin) protocol.\n\nAn equivalent issue was fixed by the [rage](https://github.com/str4d/rage) project, see advisory [GHSA-4fg7-vxc8-qx5w](https://github.com/str4d/rage/security/advisories/GHSA-4fg7-vxc8-qx5w).\n\nThanks to ⬡-49016 for reporting this.","published":"2024-12-18T18:23:06Z","modified":"2026-09-10T03:50:21.154631128Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"filippo.io/age","fixedVersion":"1.2.1"}],"fix":{"url":"https://github.com/FiloSottile/age/commit/482cf6fc9babd3ab06f6606762aac10447222201","label":"FiloSottile/age@482cf6f"},"references":[{"type":"WEB","url":"https://github.com/FiloSottile/age/security/advisories/GHSA-32gq-x56h-299c"},{"type":"WEB","url":"https://github.com/str4d/rage/security/advisories/GHSA-4fg7-vxc8-qx5w"},{"type":"WEB","url":"https://github.com/FiloSottile/age/commit/482cf6fc9babd3ab06f6606762aac10447222201"},{"type":"PACKAGE","url":"https://github.com/FiloSottile/age"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-10T03:50:21.154631128Z"}}