HashiCorp go-slug up to 0.4.3 did not fully protect against directory traversal while unpacking tar archives, and protections could be bypassed with specific constructions of multiple symlinks. Fixed in 0.5.0.
{ "binaries": [ { "binary_name": "golang-github-hashicorp-go-slug-dev", "binary_version": "0.7.0-1ubuntu1" } ] }