Sender can cause a receiver to overwrite files during ZIP extraction in Croc in github.com/schollz/croc
go package report
Is github.com/schollz/croc/v6 safe?
1 known vulnerability.
// reach
0 direct dependencies
none carry a known advisory
0 packages depend on it
an advisory here reaches each of them
Create a free accountfor every dependency path, dependent and what to upgrade
// ai model usage
Tracked for PyPI packages. HuggingFace models declare Python dependencies, so go packages are not covered.
cvss
not scored
severity out of 10
epss
0.00%
low
chance of exploitation in 30 days, 29th percentile of all CVEs
xyz score
not scored
CyberXYZ composite out of 10
fig. 01 — GHSA-8c8w-f7wp-2jr2, the advisory selected below
// 1 advisories
Checked 2026-10-01 at 00:05 UTC. The most recent advisory here was published 2024-08-21. Updated continuously from NVD, GHSA, OSV and CNA feeds.