VDB
KO

GO-2026-6284

3X-UI Vulnerable to Authenticated Arbitrary File Write via Database Import and Xray Log Path Manipulation in github.com/mhsanaei/3x-ui

Quick fix

GO-2026-6284 — github.com/mhsanaei/3x-ui/v3: upgrade to the fixed version with the command below.

go get github.com/mhsanaei/3x-ui/v3@v3.3.1

Details

3X-UI Vulnerable to Authenticated Arbitrary File Write via Database Import and Xray Log Path Manipulation in github.com/mhsanaei/3x-ui

Are you affected?

Enter the version of the package you're using.

Affected packages

Go / github.com/mhsanaei/3x-ui
Introduced in: 0

No fixed version published yet for github.com/mhsanaei/3x-ui (go modules). Pin to a known-safe version or switch to an alternative.

Go / github.com/mhsanaei/3x-ui/v2
Introduced in: 0

No fixed version published yet for github.com/mhsanaei/3x-ui/v2 (go modules). Pin to a known-safe version or switch to an alternative.

Go / github.com/mhsanaei/3x-ui/v3
Introduced in: 0 Fixed in: 3.3.1
Fix go get github.com/mhsanaei/3x-ui/v3@v3.3.1

References