blob: f24ff6e6e180a3687470770299d5ddd70e99d5bb [file]
id: GO-2026-4308
modules:
- module: github.com/go-shiori/shiori
unsupported_versions:
- last_affected: 1.7.4
vulnerable_at: 1.8.0
summary: Shiori is vulnerable to authentication bypass via a brute force attack in github.com/go-shiori/shiori
cves:
- CVE-2025-60538
ghsas:
- GHSA-mw8h-g64c-rxv4
references:
- advisory: https://github.com/advisories/GHSA-mw8h-g64c-rxv4
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2025-60538
- report: https://github.com/go-shiori/shiori/issues/1138
source:
id: GHSA-mw8h-g64c-rxv4
created: 2026-01-13T10:43:14.380500852-05:00
review_status: UNREVIEWED