Version 7bdca06d0edf of the github.com/PromonLogicalis/asn1 module contains malicious code which downloads a program from a remote web server and executes it.
{ "url": "https://pkg.go.dev/vuln/GO-2024-3012", "review_status": "REVIEWED" }