top of page
perceptive_background_267k.jpg

Billy is an interface filesystem abstraction for Go. Prior to 5.9.0, multiple path traversal issues exist across different components of go-billy. Insufficient …

Published:

27 mei 2026 om 22:00:00

Alert date:

28 mei 2026 om 23:02:47

Source:

nvd.nist.gov

Click to open the original link from this advisory

Supply Chain & Dependencies, Web Technologies

Billy, an interface filesystem abstraction for Go, contains multiple path traversal vulnerabilities prior to version 5.9.0. The vulnerabilities stem from insufficient path sanitization and boundary enforcement, allowing attackers to craft paths using '..' to escape intended base directories. While go-billy wasn't originally designed as a security boundary, inconsistent implementations across built-in components create scenarios where applications relying on go-billy for isolation may inadvertently expose access to unintended filesystem locations. The vulnerability affects applications using go-billy components for filesystem operations and has been fixed in version 5.9.0.

Technical details

Mitigation steps:

Affected products:

go-billy

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page