CVE-2025-22873
EUVD-2025-20686304.02.2026, 23:15
It was possible to improperly access the parent directory of an os.Root by opening a filename ending in "../". For example, Root.Open("../") would open the parent directory of the Root. This escape only permits opening the parent directory itself, not ancestors of the parent or files contained within the parent.EnginsightAffected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| golang | go | 𝑥 < 1.23.9 |
| golang | go | 1.24.0 ≤ 𝑥 < 1.24.3 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases