fig. 01 — GHSA-5qww-56gc-f66c, the advisory selected below
// advisories
GHSA-5qww-56gc-f66c
CRITICALCVE-2024-28892
An OS command injection vulnerability exists in the name parameter of GoCast 1.1.3. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.