Record summary

CVE-2024-33434 has a selected CVSS score of 9.8 (critical).

Description

An issue in tiagorlampert CHAOS v5.0.1 before 1b451cf62582295b7225caf5a7b506f0bad56f6b and 24c9e109b5be34df7b2bce8368eae669c481ed5e allows a remote attacker to execute arbitrary code via the unsafe concatenation of the `filename` argument into the `buildStr` string without any sanitization or filtering.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Aug 27, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated May 7, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: unknown

VulnCheck, CVE List- to < 1b451cf62582295b7225caf5a7b506f0bad56f6baffected

github.com/tiagorlampert/CHAOS

Browse Go / github.com/tiagorlampert/CHAOS
GitHub AdvisoryBefore 0.0.0-20220716132853-b47438d36e3a · Fixed in 0.0.0-20220716132853-b47438d36e3aaffected

References

8