CVE-2023-27475

HIGH

goutil < 0.6.0 - Path Traversal via ZipSlip in fsutil.Unzip

Title source: llm
STIX 2.1

Description

Goutil is a collection of miscellaneous functionality for the go language. In versions prior to 0.6.0 when users use fsutil.Unzip to unzip zip files from a malicious attacker, they may be vulnerable to path traversal. This vulnerability is known as a ZipSlip. This issue has been fixed in version 0.6.0, users are advised to upgrade. There are no known workarounds for this issue.

Scores

CVSS v3 8.8
EPSS 0.0085
EPSS Percentile 53.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-22
Status published
Products (2)
gookit/goutil 0 - 0.6.0Go
goutil_project/goutil < 0.6.0
Published Mar 07, 2023
Tracked Since Feb 18, 2026