VDB
Sign up
HIGH7.5

GHSA-vpx7-vm66-qx8r

Path Traversal in github.com/unknwon/cae/zip

Quick fix

GHSA-vpx7-vm66-qx8r — github.com/unknwon/cae: upgrade to the fixed version with the command below.

go get github.com/unknwon/cae@v1.0.1

Details

The ExtractTo function doesn't securely escape file paths in zip archives which include leading or non-leading "..". This allows an attacker to add or replace files system-wide.

### Specific Go Packages Affected github.com/unknwon/cae/zip

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/unknwon/cae
Introduced in: 0Fixed in: 1.0.1
Fixgo get github.com/unknwon/cae@v1.0.1

References