—
GO-2025-3584
go.rgst.io/stencil/v2 vulnerable to Path Traversal
Quick fix
GO-2025-3584 — go.rgst.io/stencil/v2: upgrade to the fixed version with the command below.
go get go.rgst.io/stencil/v2@v2.3.0Details
go.rgst.io/stencil/v2 vulnerable to Path Traversal
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/go.rgst.io/stencil
Introduced in:
0No fixed version published yet for go.rgst.io/stencil (go modules). Pin to a known-safe version or switch to an alternative.
References
- https://github.com/rgst-io/stencil/security/advisories/GHSA-p799-q2pr-6mxj[ADVISORY]
- https://github.com/jaredallard/archives/security/advisories/GHSA-j95m-rcjp-q69h[WEB]
- https://github.com/rgst-io/stencil/commit/5482fcada0c6f77d903d13129bd656b7df80ac3a[WEB]
- https://github.com/rgst-io/stencil/pull/255[WEB]