---
id: GHSA-32gq-x56h-299c
aliases:
  - GO-2024-3344
title: >-
  age vulnerable to malicious plugin names, recipients, or identities causing
  arbitrary binary execution
summary: >-
  age vulnerable to malicious plugin names, recipients, or identities causing
  arbitrary binary execution
severity: medium
vendor: age
product: filippo.io/age
ecosystem: go
affected:
  - filippo.io/age < 1.2.1
patched:
  - filippo.io/age 1.2.1
published: '2024-12-18'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T03:50:21.154631128Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-32gq-x56h-299c'
references:
  - url: 'https://github.com/FiloSottile/age/security/advisories/GHSA-32gq-x56h-299c'
  - url: 'https://github.com/str4d/rage/security/advisories/GHSA-4fg7-vxc8-qx5w'
  - url: >-
      https://github.com/FiloSottile/age/commit/482cf6fc9babd3ab06f6606762aac10447222201
  - url: 'https://github.com/FiloSottile/age'
tags:
  - osv
  - go
ingestedAt: '2026-09-12T03:13:01.747Z'
---

## Overview

A plugin name containing a path separator may allow an attacker to execute an arbitrary binary.

Such a plugin name can be provided to the age CLI through an attacker-controlled recipient or identity string, or to the [`plugin.NewIdentity`](https://pkg.go.dev/filippo.io/age/plugin#NewIdentity), [`plugin.NewIdentityWithoutData`](https://pkg.go.dev/filippo.io/age/plugin#NewIdentityWithoutData), or [`plugin.NewRecipient`](https://pkg.go.dev/filippo.io/age/plugin#NewRecipient) APIs.

On UNIX systems, a directory matching `${TMPDIR:-/tmp}/age-plugin-*` needs to exist for the attack to succeed.

The binary is executed with a single flag, either `--age-plugin=recipient-v1` or `--age-plugin=identity-v1`. The standard input includes the recipient or identity string, and the random file key (if encrypting) or the header of the file (if decrypting). The format is constrained by the [age-plugin](https://c2sp.org/age-plugin) protocol.

An equivalent issue was fixed by the [rage](https://github.com/str4d/rage) project, see advisory [GHSA-4fg7-vxc8-qx5w](https://github.com/str4d/rage/security/advisories/GHSA-4fg7-vxc8-qx5w).

Thanks to ⬡-49016 for reporting this.

## Affected packages

- `filippo.io/age < 1.2.1`

## Remediation

Upgrade to a patched release:

- `filippo.io/age 1.2.1`
