Tracked for PyPI packages. HuggingFace models declare Python dependencies, so go packages are not covered.
cvss
not scored
severity out of 10
epss
not scored
chance of exploitation in 30 days
xyz score
not scored
CyberXYZ composite out of 10
fig. 01 — GO-2024-3293, the advisory selected below
// 1 advisories
GO-2024-3293
UNKNOWN
Static file serving using router.Static and osfs.FS allows clients to access any file on the host file system using relative paths because the requested path is not sanitized and . and .. segments are accepted. The files will be returned as a response, provided the system user running the Go application has read access to the requested file.
As a workaround, use fsutil.NewEmbed(embeddedFS) from the goyave.dev/goyave/v5/util/fsutil package to serve static content using Router.Static instead of &osfs.FS. Embedded file systems are rooted to the specified directory, making it impossible to navigate outside of the developers' intended directory.
Checked 2026-10-01 at 00:07 UTC. The most recent advisory here was published 2024-12-13. Updated continuously from NVD, GHSA, OSV and CNA feeds.