Skip to main content
Version: latest

CVE-2022-30580

CVE Details

Visit the official vulnerability details page for CVE-2022-30580 to learn more.

Initial Publication

01/20/2025

Last Update

10/14/2025

Third Party Dependency

go

NIST CVE Summary

Code injection in Cmd.Start in os/exec before Go 1.17.11 and Go 1.18.3 allows execution of any binaries in the working directory named either "..com" or "..exe" by calling Cmd.Run, Cmd.Start, Cmd.Output, or Cmd.CombinedOutput when Cmd.Path is unset.

CVE Severity

7.8

Our Official Summary

This vulnerability is a false positive. Although this is reported by the scanning tools on some of the components, further checks indicate the symbol/function with the vulnerability while present is not being used.

Status

Ongoing

Affected Products & Versions

This CVE is non-impacting as the impacting symbol and/or function is not used in the product

Revision History

DateRevision
10/14/2025Status changed from Open to Ongoing