VYPR
High severity8.1GHSA Advisory· Published May 28, 2026· Updated May 29, 2026

CVE-2026-44973

CVE-2026-44973

Description

Billy is an interface filesystem abstraction for Go. Prior to 5.9.0, multiple path traversal issues exist across different components of go-billy. Insufficient path sanitization and boundary enforcement may allow crafted paths (e.g., using ..) to escape intended base directories. While go-billy was not originally designed to provide a strong security boundary, some of these issues were inconsistent across some of the built-in implementations. This results in scenarios where applications relying on go-billy for some level of isolation may inadvertently expose access to unintended filesystem locations. This vulnerability is fixed in 5.9.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/go-git/go-billy/v5Go
< 5.9.05.9.0
github.com/go-git/go-billy/v6Go
< 6.0.0-alpha.16.0.0-alpha.1

Affected products

73

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.