—
GO-2025-3457
WhoDB allows parameter injection in DB connection URIs leading to local file inclusion in github.com/clidey/whodb/core
Quick fix
GO-2025-3457 — github.com/clidey/whodb/core: upgrade to the fixed version with the command below.
go get github.com/clidey/whodb/core@v0.0.0-20250127202645-8d67b767e005Details
WhoDB allows parameter injection in DB connection URIs leading to local file inclusion in github.com/clidey/whodb/core
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/clidey/whodb/core
Introduced in:
0Fixed in: 0.0.0-20250127202645-8d67b767e005Fix
go get github.com/clidey/whodb/core@v0.0.0-20250127202645-8d67b767e005References
- https://github.com/clidey/whodb/security/advisories/GHSA-c7w4-9wv8-7x7c[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2025-24787[ADVISORY]
- https://github.com/clidey/whodb/commit/8d67b767e00552e5eba2b1537179b74bfa662ee1[WEB]
- https://github.com/go-sql-driver/mysql/blob/7403860363ca112af503b4612568c3096fecb466/infile.go#L128[WEB]