


Perceptive Security
SOC/SIEM Consultancy

Billy is an interface filesystem abstraction for Go. Prior to 5.9.0, multiple path traversal issues exist across different components of go-billy. Insufficient …
Published:
27 mei 2026 om 22:00:00
Alert date:
28 mei 2026 om 23:02:47
Source:
nvd.nist.gov
Supply Chain & Dependencies, Web Technologies
Billy, an interface filesystem abstraction for Go, contains multiple path traversal vulnerabilities prior to version 5.9.0. The vulnerabilities stem from insufficient path sanitization and boundary enforcement, allowing attackers to craft paths using '..' to escape intended base directories. While go-billy wasn't originally designed as a security boundary, inconsistent implementations across built-in components create scenarios where applications relying on go-billy for isolation may inadvertently expose access to unintended filesystem locations. The vulnerability affects applications using go-billy components for filesystem operations and has been fixed in version 5.9.0.
Technical details
Mitigation steps:
Affected products:
go-billy
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-44973
https://github.com/go-git/go-billy/security/advisories/GHSA-qw64-3x98-g7q2
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
