Github.Com Hashicorp Go-Slug vulnerabilities
2 known vulnerabilities affecting github.com/hashicorp_go-slug.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1
Vulnerabilities
Page 1 of 1
CVE-2025-0377CRITICALCVSS 9.1≥ 0, < 0.16.32025-01-21
CVE-2025-0377 [CRITICAL] CWE-59 HashiCorp go-slug Vulnerable to Zip Slip Attack
HashiCorp go-slug Vulnerable to Zip Slip Attack
## Summary
HashiCorp’s go-slug library is vulnerable to a zip-slip style attack when a non-existing user-provided path is extracted from the tar entry. This vulnerability, identified as CVE-2025-0377, is fixed in go-slug 0.16.3.
## Background
HashiCorp’s go-slug shared library offers functions for packing and unpacking Terraform Enterprise compatible slugs. Slugs are
ghsaosv
CVE-2020-29529HIGH≥ 0, < 0.5.02023-02-06
CVE-2020-29529 [HIGH] CWE-22 Unsafe tar unpacking in HashiCorp go-slug
Unsafe tar unpacking in HashiCorp go-slug
HashiCorp go-slug before 0.5.0 does not address attempts at directory traversal involving ../ and symlinks.
ghsaosv