CVE-2025-0377: Hashicorp Go-Slug

Critical severity, CVSS 9.1. EPSS: 0.7% chance of exploitation in the next 30 days.

HashiCorp’s go-slug library is vulnerable to a zip-slip style attack when a non-existing user-provided path is extracted from the tar entry.

Affected products

  • Hashicorp Go-Slug: before 0.16.3 (fixed in 0.16.3)

Published 2025-01-21. Last modified 2026-06-17.