CVE-2025-0377
21.01.2025, 16:15
HashiCorps go-slug library is vulnerable to a zip-slip style attack when a non-existing user-provided path is extracted from the tar entry.
Awaiting analysis
This vulnerability is currently awaiting analysis.
HashiCorps go-slug library is vulnerable to a zip-slip style attack when a non-existing user-provided path is extracted from the tar entry.