HashiCorp go-slug before 0.5.0 does not address attempts at directory traversal involving ../ and symlinks.
{
"nvd_published_at": null,
"severity": "HIGH",
"cwe_ids": [
"CWE-22",
"CWE-59"
],
"github_reviewed": true,
"github_reviewed_at": "2023-02-06T23:16:16Z"
}