Extract has insufficient checks allowing attacker to create symlinks outside the extraction directory. in github.com/codeclysm/extract
{ "review_status": "UNREVIEWED", "url": "https://pkg.go.dev/vuln/GO-2024-3196" }
"https://vuln.go.dev/ID/GO-2024-3196.json"