go package report

Is github.com/saltbo/zpan safe?

1 known vulnerability, worst severity MEDIUM.

cvss
6.3

how bad it is if exploited, out of 10

epss
0.40%

chance of exploitation in the next 30 days

xyz score
not scored

CyberXYZ composite, out of 10

fig. 01 — GHSA-2hfh-94w5-wxvf, the advisory selected below

// advisories

GHSA-2hfh-94w5-wxvf

MEDIUMCVE-2025-7453

A vulnerability was found in saltbo zpan up to 1.6.5/1.7.0-beta2. It has been rated as problematic. This issue affects the function NewToken of the file zpan/internal/app/service/token.go of the component JSON Web Token Handler. The manipulation with the input 123 leads to use of hard-coded password. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation

Affected
>=0, <1.6.6
Fixed in
1.6.6
Weakness
CWE-259
Published
2025-07-11
Source
github

GHSANVDMITRE


// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so go packages are not covered.


Checked 2026-09-22 at 01:42 UTC. The most recent advisory here was published 2025-07-11. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is github.com/saltbo/zpan safe? go package security report | CyberXYZ