go.k6.io/xk6 is vulnerable to Path Traversal
67
Medium Risk
Affected versions of this package used path handling based on filepath.Walk(dir, ...), which could allow file operations to escape the intended customization directory if untrusted paths, symlinks, or traversal primitives were present. An attacker able to influence repository contents or filesystem layout might exploit this to make the process read, modify, or overwrite files outside the target directory, potentially impacting sensitive files on the host.
You are affected if you are using a version that falls within the vulnerable range.
go.k6.io/xk6 is vulnerable to Path Traversal in versions 0.20.0 - 1.3.5.
Upgrade the go.k6.io/xk6 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant