← Back to browse · API

CVE-2024-3566

Severity
CRITICAL
CVSS
9.8
EPSS
0.06883
Risk score
41.61
CISA KEV
No
PoC
No
Published
2024-04-10
Modified
2025-11-18
First seen
2026-08-07
Aliases
EUVD-2024-32152, GHSA-9XCH-XVJ3-FMF3
Products
Go Programming Language:GoLang *, Haskell Programming Language:Haskel *, Node.js:Node.js * ≤21.7.2
Sources
euvd EUVD-2024-32152

Description

A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly depend on the CreateProcess function when the specific conditions are satisfied.

References