QID 995624

Date Published: 2023-10-25

QID 995624: GO (Go) Security Update for github.com/arduino/arduino-create-agent (GHSA-m5jc-r4gf-c6p8)

The vulnerability affects the endpoint /v2/pkgs/tools/installed and the way it handles plugin names supplied as user input. A user who has the ability to perform HTTP requests to the localhost interface, or is able to bypass the CORS configuration, can delete arbitrary files or folders belonging to the user that runs the Arduino Create Agent via a crafted HTTP POST request. Further details are available in the references.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as High - 7.1 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Github security advisory GHSA-m5jc-r4gf-c6p8 for updates and patch information.
    Vendor References

    CVEs related to QID 995624

    Software Advisories
    Advisory ID Software Component Link
    GHSA-m5jc-r4gf-c6p8 github.com/arduino/arduino-create-agent URL Logo github.com/advisories/GHSA-m5jc-r4gf-c6p8