CVE-2025-0377: Hashicorp Go-Slug
Critical severity, CVSS 9.1. EPSS: 0.7% chance of exploitation in the next 30 days.
HashiCorp’s go-slug library is vulnerable to a zip-slip style attack when a non-existing user-provided path is extracted from the tar entry.
Affected products
- Hashicorp Go-Slug: before 0.16.3 (fixed in 0.16.3)
Published 2025-01-21. Last modified 2026-06-17.