go package report

Is github.com/snapcore/snapd safe?

5 known vulnerabilities, worst severity HIGH.

cvss
8.1

how bad it is if exploited, out of 10

epss
0.80%

chance of exploitation in the next 30 days

xyz score
not scored

CyberXYZ composite, out of 10

fig. 01 — GHSA-p9v8-q5m4-pf46, the advisory selected below

// advisories

GHSA-p9v8-q5m4-pf46

HIGHCVE-2024-5138

A snap with prior permissions to create a mount entry on the host, such as firefox, normally uses the permission from one of the per-snap hook programs. A unprivileged users cannot normally trigger that behaviour by using snap run --shell firefox followed by snapctl mount, since snapd validates the requesting user identity (root or non-root). The issue allows unprivileged users to bypass that chec

Affected
>=0
Fixed in
2.63.1
Published
2025-01-16
Source
github

GHSANVDMITRE


// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so go packages are not covered.


Checked 2026-09-22 at 01:37 UTC. The most recent advisory here was published 2025-01-16. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is github.com/snapcore/snapd safe? go package security report | CyberXYZ