blob: fe21950b3df508c17581ac8d52dc5a67f6230eca [file] [log] [blame]
id: GO-2025-3895
modules:
- module: github.com/hydraide/hydraide
versions:
- fixed: 0.0.0-20250816184905-1256db38c33c
non_go_versions:
- introduced: 2.1.1
- fixed: 2.2.1
summary: HydrAIDE Authentication Bypass Vulnerability in github.com/hydraide/hydraide
ghsas:
- GHSA-qp7j-x725-g67f
references:
- advisory: https://github.com/hydraide/hydraide/security/advisories/GHSA-qp7j-x725-g67f
- fix: https://github.com/hydraide/hydraide/commit/b252554a811400a81951dc9f959b99077f187975#diff-63efbc8179fff403eb5cc642407b33c0fb21aea2c84baaf5e5223f76f5d75f55
notes:
- fix: 'github.com/hydraide/hydraide: could not add vulnerable_at: cannot auto-guess when fixed version is 0.0.0 pseudo-version'
source:
id: GHSA-qp7j-x725-g67f
created: 2025-08-27T18:27:32.143997228Z
review_status: UNREVIEWED