github.com/cyphar/filepath-securejoin is vulnerable to Path Traversal
72
High Risk
Affected versions of this package are affected by Path Traversal due to an insecure join method that fails to ensure that the root path is safe using filepath.Clean. This vulnerability could allow an attacker to exploit the root path by tricking the function into resolving a path outside the intended directory structure. As a result, this opens the door to directory traversal attacks, enabling the attacker to access or manipulate files in unauthorized locations if the caller does not validate the root path.
You are affected if you are using a version that falls within the vulnerable range.
github.com/cyphar/filepath-securejoin is vulnerable to Path Traversal in versions 0.1.0 - 0.3.6.
Upgrade the github.com/cyphar/filepath-securejoin library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant