age v1.2.1 fixes a security vulnerability in the CLI and in the plugin Go package.
An attacker that controls a recipient, identity, or plugin name could cause age to execute arbitrary binaries. On Linux and macOS, the attacker needs some control over $TMPDIR.
Advisory: https://github.com/FiloSottile/age/security/advisories/GHSA-32gq-x56h-299c
Release: https://github.com/FiloSottile/age/releases/tag/v1.2.1
Also fixed in rage: https://github.com/str4d/rage/security/advisories/GHSA-4fg7-vxc8-qx5w
Thanks to ⬡-49016 for reporting this!
GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.
All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.