On Windows, executing Cmd.Run, Cmd.Start, Cmd.Output, or Cmd.CombinedOutput when Cmd.Path is unset will unintentionally trigger execution of any binaries in the working directory named either "..com" or "..exe".
{ "url": "https://pkg.go.dev/vuln/GO-2022-0532", "review_status": "REVIEWED" }