Vendor
high
advisory
Symlink Traversal Vulnerability in go-git
1 TTP 1 CVEA symlink traversal vulnerability in the go-git library (CVE-2026-71556) enables unauthorized write access outside of the intended worktree directory when processing malicious symbolic links.
go-git v5 +2
1t
1c
updated
high
advisory
go-billy Path Traversal Vulnerabilities
2 rules 1 TTPMultiple path traversal vulnerabilities exist in go-billy, particularly affecting the `osfs.ChrootOS` implementation, where crafted paths can escape intended base directories due to insufficient path sanitization and boundary enforcement; users requiring stronger security should upgrade to v6 and use `os.Root`.
go-billy/v5 +1
path-traversal
go-billy
CVE-2026-44973
2r
1t