Klever-Go Account takeover: kleverUpdateAccountPermission authorizes on attacker-controlled RecipientAddr instead of the authenticated caller in github.com/klever-io/klever-go
{
"review_status": "UNREVIEWED",
"url": "https://pkg.go.dev/vuln/GO-2026-6582"
}