{"schema_version":"1.7.5","id":"GO-2026-4854","published":"2026-03-26T20:33:09Z","modified":"2026-03-26T21:04:16.906081Z","aliases":["CVE-2026-24516","GHSA-fh3m-562m-w4f6"],"summary":"DigitalOcean Droplet Agent: Command Injection via Metadata Service Endpoint in github.com/digitalocean/droplet-agent","details":"DigitalOcean Droplet Agent: Command Injection via Metadata Service Endpoint in github.com/digitalocean/droplet-agent","affected":[{"package":{"name":"github.com/digitalocean/droplet-agent","ecosystem":"Go","purl":"pkg:golang/github.com/digitalocean/droplet-agent"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-4854.json"}}],"references":[{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-fh3m-562m-w4f6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-24516"},{"type":"WEB","url":"https://github.com/digitalocean/droplet-agent/blob/main/internal/troubleshooting/actioner/actioner.go"},{"type":"WEB","url":"https://github.com/digitalocean/droplet-agent/blob/main/internal/troubleshooting/command/command.go"},{"type":"WEB","url":"https://github.com/digitalocean/droplet-agent/blob/main/internal/troubleshooting/command/exec.go"},{"type":"WEB","url":"https://github.com/poxsky/CVE-2026-24516-DigitalOcean-RCE"}],"database_specific":{"review_status":"UNREVIEWED","url":"https://pkg.go.dev/vuln/GO-2026-4854"}}