—
GO-2026-6284
3X-UI Vulnerable to Authenticated Arbitrary File Write via Database Import and Xray Log Path Manipulation in github.com/mhsanaei/3x-ui
Quick fix
GO-2026-6284 — github.com/mhsanaei/3x-ui/v3: upgrade to the fixed version with the command below.
go get github.com/mhsanaei/3x-ui/v3@v3.3.1 Details
3X-UI Vulnerable to Authenticated Arbitrary File Write via Database Import and Xray Log Path Manipulation in github.com/mhsanaei/3x-ui
Are you affected?
Enter the version of the package you're using.
Affected packages
Go / github.com/mhsanaei/3x-ui
Introduced in:
0 No fixed version published yet for github.com/mhsanaei/3x-ui (go modules). Pin to a known-safe version or switch to an alternative.
Go / github.com/mhsanaei/3x-ui/v2
Introduced in:
0 No fixed version published yet for github.com/mhsanaei/3x-ui/v2 (go modules). Pin to a known-safe version or switch to an alternative.
Go / github.com/mhsanaei/3x-ui/v3
Introduced in:
0 Fixed in: 3.3.1 Fix
go get github.com/mhsanaei/3x-ui/v3@v3.3.1