Junglewise Threat Intelligence

CVE-2024-53412: NietThijmen ShoppingCart command injection in connect function

CVE-2024-53412 · Severity: high · CVSS 8.4 · Published 2026-04-15

Vendors: Go.

Executive brief

NietThijmen ShoppingCart is a Go-based utility for managing shopping items and SSH connections. A security flaw in its connection function allows an attacker to execute unauthorized commands on the underlying system by providing a specially crafted port number or hostname. This could lead to a full system takeover or unauthorized access to sensitive data stored on the machine.

Technical details

A command injection vulnerability exists in the `connect` function within `ssh.go` of the NietThijmen ShoppingCart package. The root cause is the improper neutralization of user-supplied input (specifically the User, Host, and Port fields) when constructing a shell command string for SSH connections. An attacker can exploit this by injecting shell metacharacters (e.g., semicolons) into these fields, leading to arbitrary remote code execution (RCE) on the host system. While the CVSS vector indicates a local attack vector, the impact is high as it requires no privileges or user interaction to trigger the injected command once the connection function is invoked. As of the advisory date, no official patch has been released.

Affected products

  • NietThijmen ShoppingCart <= 0.0.0-20241101155353-3dd137080276

Timeline

  • 2024-11-01: disclosed: Issue first reported on GitHub repository
  • 2026-04-15: advisory: GitHub Advisory and NVD entry published

References