—
GO-2025-3477
S3-Proxy allows Reflected Cross-site Scripting (XSS) in template implementation in github.com/oxyno-zeta/s3-proxy
Quick fix
GO-2025-3477 — github.com/oxyno-zeta/s3-proxy: upgrade to the fixed version with the command below.
go get github.com/oxyno-zeta/s3-proxy@v0.0.0-20250220214310-c611c741ed48Details
S3-Proxy allows Reflected Cross-site Scripting (XSS) in template implementation in github.com/oxyno-zeta/s3-proxy
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/oxyno-zeta/s3-proxy
Introduced in:
0Fixed in: 0.0.0-20250220214310-c611c741ed48Fix
go get github.com/oxyno-zeta/s3-proxy@v0.0.0-20250220214310-c611c741ed48References
- https://github.com/oxyno-zeta/s3-proxy/security/advisories/GHSA-pp9m-qf39-hxjc[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2025-27088[ADVISORY]
- https://github.com/oxyno-zeta/s3-proxy/commit/c611c741ed4872ea3f46232be23bb830f96f9564[FIX]
- https://github.com/oxyno-zeta/s3-proxy/blob/master/templates/folder-list.tpl#L19C21-L19C38[WEB]
- https://github.com/oxyno-zeta/s3-proxy/releases/tag/v4.18.1[WEB]