GHSA-4r7w-gv7f-q74g
GitHub Security Advisory
⚠ Unreviewed
HIGH
Has CVE
Advisory Details
Incorrect conversion of certain invalid paths to valid, absolute paths in Clean in path/filepath before Go 1.17.11 and Go 1.18.3 on Windows allows potential directory traversal attack.
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: July 17, 2025 2:40 PM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.