—
GO-2025-3789
Snyk CLI Insertion of Sensitive Information into Log File allowed in DEBUG or DEBUG/TRACE mode in github.com/snyk/go-application-framework
Details
Snyk CLI Insertion of Sensitive Information into Log File allowed in DEBUG or DEBUG/TRACE mode in github.com/snyk/go-application-framework
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/snyk/go-application-framework
Introduced in:
0No fixed version published yet for github.com/snyk/go-application-framework (go modules). Pin to a known-safe version or switch to an alternative.
References
- https://github.com/advisories/GHSA-6hwc-9h8r-3vmf[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2025-6624[ADVISORY]
- https://github.com/snyk/go-application-framework/commit/ca7ba7d72e68455afb466a7a47bb2c9aece86c18[FIX]
- https://docs.snyk.io/snyk-cli/debugging-the-snyk-cli[WEB]
- https://github.com/snyk[WEB]
- https://github.com/snyk/cli/commit/38322f377da7e5f1391e1f641710be50989fa4df[WEB]
- https://github.com/snyk/cli/releases/tag/v1.1297.3[WEB]
- https://security.snyk.io/vuln/SNYK-JS-SNYK-10497607[WEB]