github.com/hashicorp/go-slug is vulnerable to Path Traversal
48
Medium Risk
Affected versions of this package are vulnerable to Path Traversal due to insufficient input validation in the TargetWithinRoot function of github.com/hashicorp/go-slug. An attacker can exploit this weakness by providing crafted file paths containing traversal sequences to escape the intended directory.
You are affected if you are using a version that falls within the vulnerable range.
github.com/hashicorp/go-slug is vulnerable to Path Traversal in versions 0.0.1 - 0.16.7.
Upgrade the github.com/hashicorp/go-slug library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant