← Back

Go Slug

go-slug

Vendor: Hashicorp • 2 CVEs

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hashicorp
1Go Slug
Jun 17, 2026
Jan 21, 2025
N/A· v4
9.1 CRITICAL· v3
N/A· v2
HashiCorp’s go-slug library is vulnerable to a zip-slip style attack when a non-existing user-provided path is extracted from the tar entry.
1Hashicorp
1Go Slug
Jun 17, 2026
Dec 3, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
HashiCorp go-slug up to 0.4.3 did not fully protect against directory traversal while unpacking tar archives, and protections could be bypassed with specific constructions of multiple symlinks. Fixed in 0.5.0.