
This is the exploit of CVE-2018-6574: go get RCE
This is the exploit of CVE-2018-6574: go get RCE
This vulnerability impacts Golang go get command and allows an attacker to gain code execution on a system installing their malicious library. This is a good example of a vulnerability that can be exploited using typosquatting to gain code execution on developers' workstations and production systems. This vulnerability was fixed in Go 1.8.7, 1.9.4 and 1.10rc2.