The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsA fix was pushed into the master branch but not yet published.
Affected versions of this package are vulnerable to Path Traversal in the txtar handling in sandbox.go, which writes each archive entry with os.WriteFile to a path taken from the entry name with no containment to the intended directory, and to unrestricted environment inheritance in vetCheckInDir in vet.go, which builds the go vet command environment from os.Environ() and so carries the host's $HOME into the child process. An attacker can execute code on the playground host by submitting an archive whose entry names place a go env configuration file under that $HOME, then having the submission handled through the go vet path, where the inherited $HOME causes that file to be read and its settings applied to the toolchain invocation. Neither half suffices alone, the write escape reaches the host filesystem while only one of the three paths that invoke go vet fails to restrict the environment, and users of go.dev/play are not affected directly, so the exposure falls on independent deployments of the service.