CVE-2025-22873

LOW3.8EPSS 0.00%

Improper access to parent directory of root in os

發布日:2026/2/4修改日:2026/5/15

描述

It was possible to improperly access the parent directory of an os.Root by opening a filename ending in "../". For example, Root.Open("../") would open the parent directory of the Root. This escape only permits opening the parent directory itself, not ancestors of the parent or files contained within the parent.

受影響套件(3)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1LOW3.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

參考連結(7)