{"id":"GHSA-32gq-x56h-299c","aliases":["GO-2024-3344"],"title":"age vulnerable to malicious plugin names, recipients, or identities causing arbitrary binary execution","summary":"age vulnerable to malicious plugin names, recipients, or identities causing arbitrary binary execution","severity":"medium","vendor":"age","product":"filippo.io/age","ecosystem":"go","affected":["filippo.io/age < 1.2.1"],"patched":["filippo.io/age 1.2.1"],"published":"2024-12-18","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:50:21.154631128Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-32gq-x56h-299c","references":[{"url":"https://github.com/FiloSottile/age/security/advisories/GHSA-32gq-x56h-299c"},{"url":"https://github.com/str4d/rage/security/advisories/GHSA-4fg7-vxc8-qx5w"},{"url":"https://github.com/FiloSottile/age/commit/482cf6fc9babd3ab06f6606762aac10447222201"},{"url":"https://github.com/FiloSottile/age"}],"tags":["osv","go"],"ingestedAt":"2026-09-12T03:13:01.747Z","slug":"GHSA-32gq-x56h-299c","body":"## Overview\n\nA plugin name containing a path separator may allow an attacker to execute an arbitrary binary.\n\nSuch a plugin name can be provided to the age CLI through an attacker-controlled recipient or identity string, or to the [`plugin.NewIdentity`](https://pkg.go.dev/filippo.io/age/plugin#NewIdentity), [`plugin.NewIdentityWithoutData`](https://pkg.go.dev/filippo.io/age/plugin#NewIdentityWithoutData), or [`plugin.NewRecipient`](https://pkg.go.dev/filippo.io/age/plugin#NewRecipient) APIs.\n\nOn UNIX systems, a directory matching `${TMPDIR:-/tmp}/age-plugin-*` needs to exist for the attack to succeed.\n\nThe binary is executed with a single flag, either `--age-plugin=recipient-v1` or `--age-plugin=identity-v1`. The standard input includes the recipient or identity string, and the random file key (if encrypting) or the header of the file (if decrypting). The format is constrained by the [age-plugin](https://c2sp.org/age-plugin) protocol.\n\nAn equivalent issue was fixed by the [rage](https://github.com/str4d/rage) project, see advisory [GHSA-4fg7-vxc8-qx5w](https://github.com/str4d/rage/security/advisories/GHSA-4fg7-vxc8-qx5w).\n\nThanks to ⬡-49016 for reporting this.\n\n## Affected packages\n\n- `filippo.io/age < 1.2.1`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `filippo.io/age 1.2.1`","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}