CVE-2022-41920
MEDIUMLancet < 1.3.4 and 2.0.0-2.1.10 - Path Traversal via ZipSlip in fileutil Package
Title source: llmDescription
Lancet is a general utility library for the go programming language. Affected versions are subject to a ZipSlip issue when using the fileutil package to unzip files. This issue has been addressed and a fix will be included in versions 2.1.10 and 1.3.4. Users are advised to upgrade. There are no known workarounds for this issue.
References (4)
Core 4
Core References
Patch, Third Party Advisory
https://github.com/duke-git/lancet/commit/f133b32faa05eb93e66175d01827afa4b7094572
Patch, Third Party Advisory
https://github.com/duke-git/lancet/commit/f869a0a67098e92d24ddd913e188b32404fa72c9
Issue Tracking, Third Party Advisory
https://github.com/duke-git/lancet/issues/62
Exploit, Third Party Advisory
https://github.com/duke-git/lancet/security/advisories/GHSA-pp3f-xrw5-q5j4
Scores
CVSS v3
6.3
EPSS
0.0079
EPSS Percentile
51.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-22
Status
published
Products (3)
duke-git/lancet
0 - 1.3.4Go
duke-git/lancet
2.0.0 - 2.1.10Go
lancet_project/lancet
< 1.3.4
Published
Nov 17, 2022
Tracked Since
Feb 18, 2026