—
GO-2025-4232
gardenctl is vulnerable to Command Injection when used with non‑POSIX shells in github.com/gardener/gardenctl-v2
Quick fix
GO-2025-4232 — github.com/gardener/gardenctl-v2: upgrade to the fixed version with the command below.
go get github.com/gardener/gardenctl-v2@v0.0.0-20251107111549-0bdc484cb5fbDetails
gardenctl is vulnerable to Command Injection when used with non‑POSIX shells in github.com/gardener/gardenctl-v2
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/gardener/gardenctl-v2
Introduced in:
0Fixed in: 0.0.0-20251107111549-0bdc484cb5fbFix
go get github.com/gardener/gardenctl-v2@v0.0.0-20251107111549-0bdc484cb5fb