Intel

AIKIDO-2025-10692

github.com/hashicorp/go-slug is vulnerable to Path Traversal

Path Traversal Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Oct 9, 2025

48

Medium Risk

This Affects:

GOgithub.com/hashicorp/go-slug
0.0.1 - 0.16.7
Fixed in 0.16.8
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to Path Traversal due to insufficient input validation in the TargetWithinRoot function of github.com/hashicorp/go-slug. An attacker can exploit this weakness by providing crafted file paths containing traversal sequences to escape the intended directory.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

github.com/hashicorp/go-slug is vulnerable to Path Traversal in versions 0.0.1 - 0.16.7.

How to fix this

Upgrade the github.com/hashicorp/go-slug library to the patch version.