Vulnerabilities
Vulnerable Software
Hashicorp:  >> Go-Slug  >> 0.4.0  Security Vulnerabilities
HashiCorp go-slug 0.4.0 through 0.18.2 could allow a local attacker to bypass .terraformignore exclusions and cause sensitive files to be included in Terraform slug uploads due to improper handling of Unicode normalization during path matching.
CVSS Score
5.5
EPSS Score
0.001
Published
2026-08-19
HashiCorp’s go-slug library is vulnerable to a zip-slip style attack when a non-existing user-provided path is extracted from the tar entry.
CVSS Score
7.5
EPSS Score
0.007
Published
2025-01-21
HashiCorp go-slug up to 0.4.3 did not fully protect against directory traversal while unpacking tar archives, and protections could be bypassed with specific constructions of multiple symlinks. Fixed in 0.5.0.
CVSS Score
7.5
EPSS Score
0.028
Published
2020-12-03


Contact Us

Shodan ® - All rights reserved