Recently, we discovered a new vulnerability in the go.mod file format that allows remote code execution.

This is especially concerning because it can be triggered by other users on GitHub and GitLab repositories when they upload their project to these services.

The go team has released a patch to fix this problem but it is up to each individual package maintainer whether or not they want to update their projects and release an updated version of their software with the fixed go.mod file format.).

