Known vulnerabilities in go-slug

Vendor: HashiCorp
Software: go-slug
Software CPE: cpe:2.3:a:hashicorp:go-slug:*:*:*:*:*:*:*:*
Total vulnerabilities: 2
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 8.8

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting go-slug go-slug is affected by 2 known vulnerabilities: 1 high, 1 medium Critical High Medium Low

Vulnerabilities (2)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU111999 - Improper Link Resolution Before File Access ('Link Following')
CVE-2025-0377
CWE-59 High
No
No
0.16.3 27.06.2025 SB2025062727
SB2025062728
SB2025063009
and 1 more
#VU48809 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2020-29529
CWE-22 Medium
No
No
0.5.0 03.12.2020 SB2020120722
SB2022112521
SB2021041399