📦 Go Slug

by Hashicorp

🔍 What is Go Slug?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-0377

HIGH CVSS 7.5 Jan 21, 2025

HashiCorp's go-slug library is vulnerable to a zip-slip attack when extracting tar archives with non-existing user-provided paths. This allows attackers to write arbitrary files outside the intended e...