GO-2026-5436

Source
https://pkg.go.dev/vuln/GO-2026-5436
Import Source
https://vuln.go.dev/ID/GO-2026-5436.json
JSON Data
https://api.osv.dev/v1/vulns/GO-2026-5436
Aliases
Published
2026-06-25T22:34:31Z
Modified
2026-06-25T23:00:17.318724567Z
Summary
Anyquery: AppleScript/JXA Code Injection via Unescaped URL in macOS Chrome Plugin in github.com/julien040/anyquery/plugins/brave
Details

Anyquery: AppleScript/JXA Code Injection via Unescaped URL in macOS Chrome Plugin in github.com/julien040/anyquery/plugins/brave

Database specific
{
    "url": "https://pkg.go.dev/vuln/GO-2026-5436",
    "review_status": "UNREVIEWED"
}
References

Affected packages

Go
github.com/julien040/anyquery/plugins/brave

Package

Name
github.com/julien040/anyquery/plugins/brave
View open source insights on deps.dev
Purl
pkg:golang/github.com/julien040/anyquery/plugins/brave

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.0.0-20240826075852-c651df0b8767

Database specific

source
"https://vuln.go.dev/ID/GO-2026-5436.json"
github.com/julien040/anyquery/plugins/chrome

Package

Name
github.com/julien040/anyquery/plugins/chrome
View open source insights on deps.dev
Purl
pkg:golang/github.com/julien040/anyquery/plugins/chrome

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.0.0-20240826075852-c651df0b8767

Database specific

source
"https://vuln.go.dev/ID/GO-2026-5436.json"
github.com/julien040/anyquery/plugins/edge

Package

Name
github.com/julien040/anyquery/plugins/edge
View open source insights on deps.dev
Purl
pkg:golang/github.com/julien040/anyquery/plugins/edge

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.0.0-20240826075852-c651df0b8767

Database specific

source
"https://vuln.go.dev/ID/GO-2026-5436.json"
github.com/julien040/anyquery/plugins/safari

Package

Name
github.com/julien040/anyquery/plugins/safari
View open source insights on deps.dev
Purl
pkg:golang/github.com/julien040/anyquery/plugins/safari

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.0.0-20240826075852-c651df0b8767

Database specific

source
"https://vuln.go.dev/ID/GO-2026-5436.json"