Impact
An attacker can supply a malicious Go project that contains a forged golang.org/toolchain entry in go.sum and point GOMODPROXY to a malicious proxy. The Go toolchain, which normally verifies module checksums against a database, will use the bogus checksum instead of the canonical one, allowing the attacker to inject arbitrary code. This is an integrity‑verification weakness (CWE‑20), which can lead to the execution of untrusted code and compromise of confidentiality and integrity within the user’s environment.
Affected Systems
The vulnerability affects the Go toolchain’s command‑line tool cmd/go across all installed versions; specific affected releases were not listed by the CNA. Users running any Go toolchain that fetches modules through GOMODPROXY are potentially impacted.
Risk and Exploitability
The exploit requires that the vulnerable user runs a Go project that references the fake golang.org/toolchain checksum and uses a malicious module proxy. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score is not provided. Given the supply‑chain nature of the attack, the risk is considered significant for environments that trust external module proxies.
OpenCVE Enrichment