blob: ddfb17db6d16572b271c443cf8877fa4dddb426d [file]
id: GO-2026-4844
modules:
- module: github.com/tobychui/zoraxy
versions:
- fixed: 3.3.2+incompatible
vulnerable_at: 3.3.2-rc4+incompatible
summary: 'Zoraxy: Authenticated Path Traversal in Config Import leads to RCE in github.com/tobychui/zoraxy'
cves:
- CVE-2026-33529
ghsas:
- GHSA-7pq3-326h-f8q9
references:
- advisory: https://github.com/tobychui/zoraxy/security/advisories/GHSA-7pq3-326h-f8q9
- fix: https://github.com/tobychui/zoraxy/commit/69ac755aeec5d15ba4c62099f7f1ed77a855b40b
- web: https://github.com/tobychui/zoraxy/releases/tag/v3.3.2
source:
id: GHSA-7pq3-326h-f8q9
created: 2026-03-26T15:26:41.380351137-04:00
review_status: UNREVIEWED